ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0046×

67 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupFIN7

FIN7 has collected files and other sensitive information from a compromised network.

T1008
Fallback Channels
GroupFIN7

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

T1021.001
Remote Desktop Protocol
GroupFIN7

FIN7 has used RDP to move laterally in victim environments.

T1021.004
SSH
GroupFIN7

FIN7 has used SSH to move laterally through victim environments.

T1021.005
VNC
GroupFIN7

FIN7 has used TightVNC to control compromised hosts.

T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1027.016
Junk Code Insertion
GroupFIN7

FIN7 has used random junk code to obfuscate malware code.

T1033
System Owner/User Discovery
GroupFIN7

FIN7 has used the command `cmd.exe /C quser` to collect user session information.

T1036.004
Masquerade Task or Service
GroupFIN7

FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN7

FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name.

T1047
Windows Management Instrumentation
GroupFIN7

FIN7 has used WMI to install malware on targeted systems.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1057
Process Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1059.003
Windows Command Shell
GroupFIN7

FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards.

T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1071.004
DNS
GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

T1078
Valid Accounts
GroupFIN7

FIN7 has harvested valid administrative credentials for lateral movement.

T1078.003
Local Accounts
GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

T1082
System Information Discovery
GroupFIN7

FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname.

T1087.002
Domain Account
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

T1091
Replication Through Removable Media
GroupFIN7

FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands.

T1102.002
Bidirectional Communication
GroupFIN7

FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2.

T1105
Ingress Tool Transfer
GroupFIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.

T1113
Screen Capture
GroupFIN7

FIN7 captured screenshots and desktop video recordings.

T1124
System Time Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

T1125
Video Capture
GroupFIN7

FIN7 created a custom video recording capability that could be used to monitor operations in the victim's environment.

T1140
Deobfuscate/Decode Files or Information
GroupFIN7

FIN7 has decoded a malicious PowerShell script using `certutil -decode hex` and has decoded an XOR-obfuscated block of data with the key `qawsed1q2w3e`, which led to the installation of Lizar.

T1190
Exploit Public-Facing Application
GroupFIN7

FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange.

T1195.002
Compromise Software Supply Chain
GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

T1204.001
Malicious Link
GroupFIN7

FIN7 has used malicious links to lure victims into downloading malware.

T1204.002
Malicious File
GroupFIN7

FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor.

T1210
Exploitation of Remote Services
GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

T1218.005
Mshta
GroupFIN7

FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.

T1218.011
Rundll32
GroupFIN7

FIN7 has used `rundll32.exe` to execute malware on a compromised network.

T1219
Remote Access Tools
GroupFIN7

FIN7 has utilized the remote management tool Atera to download malware to a compromised system.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1497.002
User Activity Based Checks
GroupFIN7

FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes.

T1543.003
Windows Service
GroupFIN7

FIN7 created new Windows services and added them to the startup directories for persistence.

T1546.011
Application Shimming
GroupFIN7

FIN7 has used application shim databases for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN7

FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.

T1553.002
Code Signing
GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

T1558.003
Kerberoasting
GroupFIN7

FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement.

T1559.002
Dynamic Data Exchange
GroupFIN7

FIN7 spear phishing campaigns have included malicious Word documents with DDE execution.

T1564.001
Hidden Files and Directories
GroupFIN7

FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden.

T1564.003
Hidden Window
GroupFIN7

FIN7 has used .txt files to conceal PowerShell commands.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.