Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupPatchwork | Patchwork collected and exfiltrated files from the infected system. |
| T1021.001 Remote Desktop Protocol |
GroupPatchwork | Patchwork attempted to use RDP to move laterally. |
| T1027.001 Binary Padding |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.002 Software Packing |
GroupPatchwork | A Patchwork payload was packed with UPX. |
| T1027.005 Indicator Removal from Tools |
GroupPatchwork | Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes. |
| T1027.010 Command Obfuscation |
GroupPatchwork | Patchwork has obfuscated a script with Crypto Obfuscator. |
| T1033 System Owner/User Discovery |
GroupPatchwork | Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPatchwork | Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe. |
| T1053.005 Scheduled Task |
GroupPatchwork | A Patchwork file stealer can run a TaskScheduler DLL to add persistence. |
| T1055.012 Process Hollowing |
GroupPatchwork | A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe. |
| T1059.001 PowerShell |
GroupPatchwork | Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine. |
| T1059.003 Windows Command Shell |
GroupPatchwork | Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines. |
| T1059.005 Visual Basic |
GroupPatchwork | Patchwork used Visual Basic Scripts (VBS) on victim machines. |
| T1070.004 File Deletion |
GroupPatchwork | Patchwork removed certain files and replaced them so they could not be retrieved. |
| T1074.001 Local Data Staging |
GroupPatchwork | Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server. |
| T1082 System Information Discovery |
GroupPatchwork | Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server. |
| T1083 File and Directory Discovery |
GroupPatchwork | A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions. |
| T1102.001 Dead Drop Resolver |
GroupPatchwork | Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites. |
| T1105 Ingress Tool Transfer |
GroupPatchwork | Patchwork payloads download additional files from the C2 server. |
| T1112 Modify Registry |
GroupPatchwork | A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs. |
| T1119 Automated Collection |
GroupPatchwork | Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server. |
| T1132.001 Standard Encoding |
GroupPatchwork | Patchwork used Base64 to encode C2 traffic. |
| T1189 Drive-by Compromise |
GroupPatchwork | Patchwork has used watering holes to deliver files with exploits to initial victims. |
| T1197 BITS Jobs |
GroupPatchwork | Patchwork has used BITS jobs to download malicious payloads. |
| T1203 Exploitation for Client Execution |
GroupPatchwork | Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641. |
| T1204.001 Malicious Link |
GroupPatchwork | Patchwork has used spearphishing with links to try to get users to click, download and open malicious files. |
| T1204.002 Malicious File |
GroupPatchwork | Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware. |
| T1518.001 Security Software Discovery |
GroupPatchwork | Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool). |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPatchwork | Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key. |
| T1548.002 Bypass User Account Control |
GroupPatchwork | Patchwork bypassed User Access Control (UAC). |
| T1553.002 Code Signing |
GroupPatchwork | Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies. |
| T1555.003 Credentials from Web Browsers |
GroupPatchwork | Patchwork dumped the login data database from |
| T1559.002 Dynamic Data Exchange |
GroupPatchwork | Patchwork leveraged the DDE protocol to deliver their malware. |
| T1560 Archive Collected Data |
GroupPatchwork | Patchwork encrypted the collected files' path with AES and then encoded them with base64. |
| T1566.001 Spearphishing Attachment |
GroupPatchwork | Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims. |
| T1566.002 Spearphishing Link |
GroupPatchwork | Patchwork has used spearphishing with links to deliver files with exploits to initial victims. |
| T1574.001 DLL |
GroupPatchwork | A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading. |
| T1587.002 Code Signing Certificates |
GroupPatchwork | Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware. |
| T1588.002 Tool |
GroupPatchwork | Patchwork has obtained and used open-source tools such as QuasarRAT. |
| T1598.003 Spearphishing Link |
GroupPatchwork | Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages. |
| T1680 Local Storage Discovery |
GroupPatchwork | Patchwork enumerated all available drives on the victim's machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.