ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0037×

40 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN6

FIN6 has used Windows Credential Editor for credential dumping.

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1005
Data from Local System
GroupFIN6

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1018
Remote System Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1021.001
Remote Desktop Protocol
GroupFIN6

FIN6 used RDP to move laterally in victim networks.

T1027.010
Command Obfuscation
GroupFIN6

FIN6 has used encoded PowerShell commands.

T1036.004
Masquerade Task or Service
GroupFIN6

FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service.

T1046
Network Service Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1047
Windows Management Instrumentation
GroupFIN6

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1053.005
Scheduled Task
GroupFIN6

FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1059.003
Windows Command Shell
GroupFIN6

FIN6 has used kill.bat script to disable security tools.

T1059.007
JavaScript
GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

T1068
Exploitation for Privilege Escalation
GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

T1070.004
File Deletion
GroupFIN6

FIN6 has removed files from victim machines.

T1074.002
Remote Data Staging
GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1087.002
Domain Account
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1095
Non-Application Layer Protocol
GroupFIN6

FIN6 has used Metasploit Bind and Reverse TCP stagers.

T1102
Web Service
GroupFIN6

FIN6 has used Pastebin and Google Storage to host content for their operations.

T1110.002
Password Cracking
GroupFIN6

FIN6 has extracted password hashes from ntds.dit to crack offline.

T1119
Automated Collection
GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

T1134
Access Token Manipulation
GroupFIN6

FIN6 has used has used Metasploit’s named-pipe impersonation technique to escalate privileges.

T1204.002
Malicious File
GroupFIN6

FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts.

T1213.006
Databases
GroupFIN6

FIN6 has collected schemas and user accounts from systems running SQL Server.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN6

FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD.

T1553.002
Code Signing
GroupFIN6

FIN6 has used Comodo code-signing certificates.

T1555
Credentials from Password Stores
GroupFIN6

FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP.

T1555.003
Credentials from Web Browsers
GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

T1560
Archive Collected Data
GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

T1560.003
Archive via Custom Method
GroupFIN6

FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation.

T1566.001
Spearphishing Attachment
GroupFIN6

FIN6 has targeted victims with e-mails containing malicious attachments.

T1566.003
Spearphishing via Service
GroupFIN6

FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets.

T1569.002
Service Execution
GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

T1572
Protocol Tunneling
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

T1588.002
Tool
GroupFIN6

FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind.

T1685
Disable or Modify Tools
GroupFIN6

FIN6 has deployed a utility script named kill.bat to disable anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.