Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1003.003 NTDS |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers. |
| T1003.004 LSA Secrets |
GroupDragonfly | Dragonfly has dropped and executed SecretsDump to dump password hashes. |
| T1005 Data from Local System |
GroupDragonfly | Dragonfly has collected data from local victim systems. |
| T1012 Query Registry |
GroupDragonfly | Dragonfly has queried the Registry to identify victim information. |
| T1016 System Network Configuration Discovery |
GroupDragonfly | Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain. |
| T1018 Remote System Discovery |
GroupDragonfly | Dragonfly has likely obtained a list of hosts in the victim environment. |
| T1021.001 Remote Desktop Protocol |
GroupDragonfly | Dragonfly has moved laterally via RDP. |
| T1033 System Owner/User Discovery |
GroupDragonfly | Dragonfly used the command |
| T1036.010 Masquerade Account Name |
GroupDragonfly | Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account. |
| T1053.005 Scheduled Task |
GroupDragonfly | Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files. |
| T1059 Command and Scripting Interpreter |
GroupDragonfly | Dragonfly has used the command line for execution. |
| T1059.001 PowerShell |
GroupDragonfly | Dragonfly has used PowerShell scripts for execution. |
| T1059.003 Windows Command Shell |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including batch scripts. |
| T1059.006 Python |
GroupDragonfly | Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim. |
| T1069.002 Domain Groups |
GroupDragonfly | Dragonfly has used batch scripts to enumerate administrators and users in the domain. |
| T1070.004 File Deletion |
GroupDragonfly | Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots. |
| T1071.002 File Transfer Protocols |
GroupDragonfly | Dragonfly has used SMB for C2. |
| T1074.001 Local Data Staging |
GroupDragonfly | Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it. |
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1083 File and Directory Discovery |
GroupDragonfly | Dragonfly has used a batch script to gather folder and file names from victim hosts. |
| T1087.002 Domain Account |
GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| T1098.007 Additional Local or Domain Groups |
GroupDragonfly | Dragonfly has added newly created accounts to the administrators group to maintain elevated access. |
| T1105 Ingress Tool Transfer |
GroupDragonfly | Dragonfly has copied and installed tools for operations once in the victim environment. |
| T1110 Brute Force |
GroupDragonfly | Dragonfly has attempted to brute force credentials to gain access. |
| T1110.002 Password Cracking |
GroupDragonfly | Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec. |
| T1112 Modify Registry |
GroupDragonfly | Dragonfly has modified the Registry to perform multiple techniques through the use of Reg. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1114.002 Remote Email Collection |
GroupDragonfly | Dragonfly has accessed email accounts using Outlook Web Access. |
| T1133 External Remote Services |
GroupDragonfly | Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks. |
| T1135 Network Share Discovery |
GroupDragonfly | Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems. |
| T1136.001 Local Account |
GroupDragonfly | Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target. |
| T1187 Forced Authentication |
GroupDragonfly | Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems. |
| T1189 Drive-by Compromise |
GroupDragonfly | Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit. |
| T1190 Exploit Public-Facing Application |
GroupDragonfly | Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs. |
| T1195.002 Compromise Software Supply Chain |
GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| T1203 Exploitation for Client Execution |
GroupDragonfly | Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. |
| T1204.002 Malicious File |
GroupDragonfly | Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments. |
| T1210 Exploitation of Remote Services |
GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| T1221 Template Injection |
GroupDragonfly | Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication. |
| T1505.003 Web Shell |
GroupDragonfly | Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDragonfly | Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence. |
| T1560 Archive Collected Data |
GroupDragonfly | Dragonfly has compressed data into .zip files prior to exfiltration. |
| T1564.002 Hidden Users |
GroupDragonfly | Dragonfly has modified the Registry to hide created user accounts. |
| T1566.001 Spearphishing Attachment |
GroupDragonfly | Dragonfly has sent emails with malicious attachments to gain initial access. |
| T1583.001 Domains |
GroupDragonfly | Dragonfly has registered domains for targeting intended victims. |
| T1583.003 Virtual Private Server |
GroupDragonfly | Dragonfly has acquired VPS infrastructure for use in malicious campaigns. |
| T1584.004 Server |
GroupDragonfly | Dragonfly has compromised legitimate websites to host C2 and malware modules. |
| T1588.002 Tool |
GroupDragonfly | Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec. |
| T1591.002 Business Relationships |
GroupDragonfly | Dragonfly has collected open source information to identify relationships between organizations for targeting purposes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.