Real-world descriptions of how a group, tool or campaign used a technique.
67 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupFIN7 | FIN7 has collected files and other sensitive information from a compromised network. |
| T1008 Fallback Channels |
GroupFIN7 | FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| T1021.001 Remote Desktop Protocol |
GroupFIN7 | FIN7 has used RDP to move laterally in victim environments. |
| T1021.004 SSH |
GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| T1021.005 VNC |
GroupFIN7 | FIN7 has used TightVNC to control compromised hosts. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1027.016 Junk Code Insertion |
GroupFIN7 | FIN7 has used random junk code to obfuscate malware code. |
| T1033 System Owner/User Discovery |
GroupFIN7 | FIN7 has used the command `cmd.exe /C quser` to collect user session information. |
| T1036.004 Masquerade Task or Service |
GroupFIN7 | FIN7 has created a scheduled task named “AdobeFlashSync” to establish persistence. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
| T1047 Windows Management Instrumentation |
GroupFIN7 | FIN7 has used WMI to install malware on targeted systems. |
| T1053.005 Scheduled Task |
GroupFIN7 | FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1057 Process Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1059 Command and Scripting Interpreter |
GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1059.003 Windows Command Shell |
GroupFIN7 | FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards. |
| T1059.005 Visual Basic |
GroupFIN7 | FIN7 used VBS scripts to help perform tasks on the victim's machine. |
| T1059.007 JavaScript |
GroupFIN7 | FIN7 used JavaScript scripts to help perform tasks on the victim's machine. |
| T1069.002 Domain Groups |
GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| T1071.004 DNS |
GroupFIN7 | FIN7 has performed C2 using DNS via A, OPT, and TXT records. |
| T1078 Valid Accounts |
GroupFIN7 | FIN7 has harvested valid administrative credentials for lateral movement. |
| T1078.003 Local Accounts |
GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| T1082 System Information Discovery |
GroupFIN7 | FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname. |
| T1087.002 Domain Account |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| T1091 Replication Through Removable Media |
GroupFIN7 | FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands. |
| T1102.002 Bidirectional Communication |
GroupFIN7 | FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2. |
| T1105 Ingress Tool Transfer |
GroupFIN7 | FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload. |
| T1113 Screen Capture |
GroupFIN7 | FIN7 captured screenshots and desktop video recordings. |
| T1124 System Time Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| T1125 Video Capture |
GroupFIN7 | FIN7 created a custom video recording capability that could be used to monitor operations in the victim's environment. |
| T1140 Deobfuscate/Decode Files or Information |
GroupFIN7 | FIN7 has decoded a malicious PowerShell script using `certutil -decode hex` and has decoded an XOR-obfuscated block of data with the key `qawsed1q2w3e`, which led to the installation of Lizar. |
| T1190 Exploit Public-Facing Application |
GroupFIN7 | FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange. |
| T1195.002 Compromise Software Supply Chain |
GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| T1204.001 Malicious Link |
GroupFIN7 | FIN7 has used malicious links to lure victims into downloading malware. |
| T1204.002 Malicious File |
GroupFIN7 | FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor. |
| T1210 Exploitation of Remote Services |
GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| T1218.005 Mshta |
GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| T1218.011 Rundll32 |
GroupFIN7 | FIN7 has used `rundll32.exe` to execute malware on a compromised network. |
| T1219 Remote Access Tools |
GroupFIN7 | FIN7 has utilized the remote management tool Atera to download malware to a compromised system. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1497.002 User Activity Based Checks |
GroupFIN7 | FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes. |
| T1543.003 Windows Service |
GroupFIN7 | FIN7 created new Windows services and added them to the startup directories for persistence. |
| T1546.011 Application Shimming |
GroupFIN7 | FIN7 has used application shim databases for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN7 | FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. |
| T1553.002 Code Signing |
GroupFIN7 | FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls. |
| T1558.003 Kerberoasting |
GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| T1559.002 Dynamic Data Exchange |
GroupFIN7 | FIN7 spear phishing campaigns have included malicious Word documents with DDE execution. |
| T1564.001 Hidden Files and Directories |
GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| T1564.003 Hidden Window |
GroupFIN7 | FIN7 has used .txt files to conceal PowerShell commands. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.