ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0040×

41 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupPatchwork

Patchwork collected and exfiltrated files from the infected system.

T1021.001
Remote Desktop Protocol
GroupPatchwork

Patchwork attempted to use RDP to move laterally.

T1027.001
Binary Padding
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.002
Software Packing
GroupPatchwork

A Patchwork payload was packed with UPX.

T1027.005
Indicator Removal from Tools
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.010
Command Obfuscation
GroupPatchwork

Patchwork has obfuscated a script with Crypto Obfuscator.

T1033
System Owner/User Discovery
GroupPatchwork

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1036.005
Match Legitimate Resource Name or Location
GroupPatchwork

Patchwork installed its payload in the startup programs folder as "Baidu Software Update." The group also adds its second stage payload to the startup programs as “Net Monitor." They have also dropped QuasarRAT binaries as files named microsoft_network.exe and crome.exe.

T1053.005
Scheduled Task
GroupPatchwork

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.

T1055.012
Process Hollowing
GroupPatchwork

A Patchwork payload uses process hollowing to hide the UAC bypass vulnerability exploitation inside svchost.exe.

T1059.001
PowerShell
GroupPatchwork

Patchwork used PowerSploit to download payloads, run a reverse shell, and execute malware on the victim's machine.

T1059.003
Windows Command Shell
GroupPatchwork

Patchwork ran a reverse shell with Meterpreter. Patchwork used JavaScript code and .SCT files on victim machines.

T1059.005
Visual Basic
GroupPatchwork

Patchwork used Visual Basic Scripts (VBS) on victim machines.

T1070.004
File Deletion
GroupPatchwork

Patchwork removed certain files and replaced them so they could not be retrieved.

T1074.001
Local Data Staging
GroupPatchwork

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

T1082
System Information Discovery
GroupPatchwork

Patchwork collected the victim computer name, OS version, and architecture type and sent the information to its C2 server.

T1083
File and Directory Discovery
GroupPatchwork

A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions.

T1102.001
Dead Drop Resolver
GroupPatchwork

Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites.

T1105
Ingress Tool Transfer
GroupPatchwork

Patchwork payloads download additional files from the C2 server.

T1112
Modify Registry
GroupPatchwork

A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs.

T1119
Automated Collection
GroupPatchwork

Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server.

T1132.001
Standard Encoding
GroupPatchwork

Patchwork used Base64 to encode C2 traffic.

T1189
Drive-by Compromise
GroupPatchwork

Patchwork has used watering holes to deliver files with exploits to initial victims.

T1197
BITS Jobs
GroupPatchwork

Patchwork has used BITS jobs to download malicious payloads.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1204.001
Malicious Link
GroupPatchwork

Patchwork has used spearphishing with links to try to get users to click, download and open malicious files.

T1204.002
Malicious File
GroupPatchwork

Patchwork embedded a malicious macro in a Word document and lured the victim to click on an icon to execute the malware.

T1518.001
Security Software Discovery
GroupPatchwork

Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool).

T1547.001
Registry Run Keys / Startup Folder
GroupPatchwork

Patchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.

T1548.002
Bypass User Account Control
GroupPatchwork

Patchwork bypassed User Access Control (UAC).

T1553.002
Code Signing
GroupPatchwork

Patchwork has signed malware with self-signed certificates from fictitious and spoofed legitimate software companies.

T1555.003
Credentials from Web Browsers
GroupPatchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.

T1559.002
Dynamic Data Exchange
GroupPatchwork

Patchwork leveraged the DDE protocol to deliver their malware.

T1560
Archive Collected Data
GroupPatchwork

Patchwork encrypted the collected files' path with AES and then encoded them with base64.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

T1566.002
Spearphishing Link
GroupPatchwork

Patchwork has used spearphishing with links to deliver files with exploits to initial victims.

T1574.001
DLL
GroupPatchwork

A Patchwork .dll that contains BADNEWS is loaded and executed using DLL side-loading.

T1587.002
Code Signing Certificates
GroupPatchwork

Patchwork has created self-signed certificates from fictitious and spoofed legitimate software companies that were later used to sign malware.

T1588.002
Tool
GroupPatchwork

Patchwork has obtained and used open-source tools such as QuasarRAT.

T1598.003
Spearphishing Link
GroupPatchwork

Patchwork has used embedded image tags (known as web bugs) with unique, per-recipient tracking links in their emails for the purpose of identifying which recipients opened messages.

T1680
Local Storage Discovery
GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.