ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0035×

56 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1003.003
NTDS
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes. They also obtained ntds.dit from domain controllers.

T1003.004
LSA Secrets
GroupDragonfly

Dragonfly has dropped and executed SecretsDump to dump password hashes.

T1005
Data from Local System
GroupDragonfly

Dragonfly has collected data from local victim systems.

T1012
Query Registry
GroupDragonfly

Dragonfly has queried the Registry to identify victim information.

T1016
System Network Configuration Discovery
GroupDragonfly

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.

T1018
Remote System Discovery
GroupDragonfly

Dragonfly has likely obtained a list of hosts in the victim environment.

T1021.001
Remote Desktop Protocol
GroupDragonfly

Dragonfly has moved laterally via RDP.

T1033
System Owner/User Discovery
GroupDragonfly

Dragonfly used the command query user on victim hosts.

T1036.010
Masquerade Account Name
GroupDragonfly

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

T1053.005
Scheduled Task
GroupDragonfly

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.

T1059
Command and Scripting Interpreter
GroupDragonfly

Dragonfly has used the command line for execution.

T1059.001
PowerShell
GroupDragonfly

Dragonfly has used PowerShell scripts for execution.

T1059.003
Windows Command Shell
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including batch scripts.

T1059.006
Python
GroupDragonfly

Dragonfly has used various types of scripting to perform operations, including Python scripts. The group was observed installing Python 2.7 on a victim.

T1069.002
Domain Groups
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

T1070.004
File Deletion
GroupDragonfly

Dragonfly has deleted many of its files used during operations as part of cleanup, including removing applications and deleting screenshots.

T1071.002
File Transfer Protocols
GroupDragonfly

Dragonfly has used SMB for C2.

T1074.001
Local Data Staging
GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

T1078
Valid Accounts
GroupDragonfly

Dragonfly has compromised user credentials and used valid accounts for operations.

T1083
File and Directory Discovery
GroupDragonfly

Dragonfly has used a batch script to gather folder and file names from victim hosts.

T1087.002
Domain Account
GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

T1098.007
Additional Local or Domain Groups
GroupDragonfly

Dragonfly has added newly created accounts to the administrators group to maintain elevated access.

T1105
Ingress Tool Transfer
GroupDragonfly

Dragonfly has copied and installed tools for operations once in the victim environment.

T1110
Brute Force
GroupDragonfly

Dragonfly has attempted to brute force credentials to gain access.

T1110.002
Password Cracking
GroupDragonfly

Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec.

T1112
Modify Registry
GroupDragonfly

Dragonfly has modified the Registry to perform multiple techniques through the use of Reg.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

T1114.002
Remote Email Collection
GroupDragonfly

Dragonfly has accessed email accounts using Outlook Web Access.

T1133
External Remote Services
GroupDragonfly

Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks.

T1135
Network Share Discovery
GroupDragonfly

Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems.

T1136.001
Local Account
GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

T1187
Forced Authentication
GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1190
Exploit Public-Facing Application
GroupDragonfly

Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs.

T1195.002
Compromise Software Supply Chain
GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

T1203
Exploitation for Client Execution
GroupDragonfly

Dragonfly has exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system.

T1204.002
Malicious File
GroupDragonfly

Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.

T1210
Exploitation of Remote Services
GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

T1221
Template Injection
GroupDragonfly

Dragonfly has injected SMB URLs into malicious Word spearphishing attachments to initiate Forced Authentication.

T1505.003
Web Shell
GroupDragonfly

Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.

T1547.001
Registry Run Keys / Startup Folder
GroupDragonfly

Dragonfly has added the registry value ntdll to the Registry Run key to establish persistence.

T1560
Archive Collected Data
GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

T1564.002
Hidden Users
GroupDragonfly

Dragonfly has modified the Registry to hide created user accounts.

T1566.001
Spearphishing Attachment
GroupDragonfly

Dragonfly has sent emails with malicious attachments to gain initial access.

T1583.001
Domains
GroupDragonfly

Dragonfly has registered domains for targeting intended victims.

T1583.003
Virtual Private Server
GroupDragonfly

Dragonfly has acquired VPS infrastructure for use in malicious campaigns.

T1584.004
Server
GroupDragonfly

Dragonfly has compromised legitimate websites to host C2 and malware modules.

T1588.002
Tool
GroupDragonfly

Dragonfly has obtained and used tools such as Mimikatz, CrackMapExec, and PsExec.

T1591.002
Business Relationships
GroupDragonfly

Dragonfly has collected open source information to identify relationships between organizations for targeting purposes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.