Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFIN6 | FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1005 Data from Local System |
GroupFIN6 | FIN6 has collected and exfiltrated payment card data from compromised systems. |
| T1018 Remote System Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1021.001 Remote Desktop Protocol |
GroupFIN6 | FIN6 used RDP to move laterally in victim networks. |
| T1027.010 Command Obfuscation |
GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| T1036.004 Masquerade Task or Service |
GroupFIN6 | FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1046 Network Service Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1047 Windows Management Instrumentation |
GroupFIN6 | FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN6 | FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1053.005 Scheduled Task |
GroupFIN6 | FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1059.003 Windows Command Shell |
GroupFIN6 | FIN6 has used |
| T1059.007 JavaScript |
GroupFIN6 | FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN6 | FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges. |
| T1070.004 File Deletion |
GroupFIN6 | FIN6 has removed files from victim machines. |
| T1074.002 Remote Data Staging |
GroupFIN6 | FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1087.002 Domain Account |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1095 Non-Application Layer Protocol |
GroupFIN6 | FIN6 has used Metasploit Bind and Reverse TCP stagers. |
| T1102 Web Service |
GroupFIN6 | FIN6 has used Pastebin and Google Storage to host content for their operations. |
| T1110.002 Password Cracking |
GroupFIN6 | FIN6 has extracted password hashes from ntds.dit to crack offline. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1134 Access Token Manipulation |
GroupFIN6 | FIN6 has used has used Metasploit’s named-pipe impersonation technique to escalate privileges. |
| T1204.002 Malicious File |
GroupFIN6 | FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts. |
| T1213.006 Databases |
GroupFIN6 | FIN6 has collected schemas and user accounts from systems running SQL Server. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN6 | FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. |
| T1553.002 Code Signing |
GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| T1555 Credentials from Password Stores |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP. |
| T1555.003 Credentials from Web Browsers |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| T1560 Archive Collected Data |
GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
| T1560.003 Archive via Custom Method |
GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
| T1566.001 Spearphishing Attachment |
GroupFIN6 | FIN6 has targeted victims with e-mails containing malicious attachments. |
| T1566.003 Spearphishing via Service |
GroupFIN6 | FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets. |
| T1569.002 Service Execution |
GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| T1572 Protocol Tunneling |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1588.002 Tool |
GroupFIN6 | FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind. |
| T1685 Disable or Modify Tools |
GroupFIN6 | FIN6 has deployed a utility script named |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.