ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0035×

56 examples

TechniqueUsed byProcedure example
T1595.002
Vulnerability Scanning
GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

T1598.002
Spearphishing Attachment
GroupDragonfly

Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials.

T1598.003
Spearphishing Link
GroupDragonfly

Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites.

T1608.004
Drive-by Target
GroupDragonfly

Dragonfly has compromised websites to redirect traffic and to host exploit kits.

T1685.005
Clear Windows Event Logs
GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

T1686
Disable or Modify System Firewall
GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.