Real-world descriptions of how a group, tool or campaign used a technique.
67 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
GroupFIN7 | FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.” |
| T1567.002 Exfiltration to Cloud Storage |
GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
| T1569.002 Service Execution |
GroupFIN7 | FIN7 has started the SSH service by executing `sc start sshd`. |
| T1571 Non-Standard Port |
GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| T1572 Protocol Tunneling |
GroupFIN7 | FIN7 has tunneled C2 traffic via OpenSSH. |
| T1583.001 Domains |
GroupFIN7 | FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable. |
| T1583.006 Web Services |
GroupFIN7 | FIN7 has set up Amazon S3 buckets to host trojanized digital products. |
| T1587.001 Malware |
GroupFIN7 | FIN7 has developed malware for use in operations, including the creation of infected removable media. |
| T1588.002 Tool |
GroupFIN7 | FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts. |
| T1591 Gather Victim Org Information |
GroupFIN7 | FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information. |
| T1591.004 Identify Roles |
GroupFIN7 | FIN7 has identified IT staff and employees who had higher levels of administrative rights. |
| T1608.001 Upload Malware |
GroupFIN7 | FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip. |
| T1608.004 Drive-by Target |
GroupFIN7 | FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products. |
| T1608.005 Link Target |
GroupFIN7 | FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable. |
| T1620 Reflective Code Loading |
GroupFIN7 | FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`. |
| T1674 Input Injection |
GroupFIN7 | FIN7 has used malicious USBs to emulate keystrokes to launch PowerShell to download and execute malware from the adversary's server. |
| T1686 Disable or Modify System Firewall |
GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.