ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0046×

67 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
GroupFIN7

FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.”

T1567.002
Exfiltration to Cloud Storage
GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

T1569.002
Service Execution
GroupFIN7

FIN7 has started the SSH service by executing `sc start sshd`.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

T1572
Protocol Tunneling
GroupFIN7

FIN7 has tunneled C2 traffic via OpenSSH.

T1583.001
Domains
GroupFIN7

FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable.

T1583.006
Web Services
GroupFIN7

FIN7 has set up Amazon S3 buckets to host trojanized digital products.

T1587.001
Malware
GroupFIN7

FIN7 has developed malware for use in operations, including the creation of infected removable media.

T1588.002
Tool
GroupFIN7

FIN7 has utilized a variety of tools such as Cobalt Strike, PowerSploit, and the remote management tool, Atera for targeting efforts.

T1591
Gather Victim Org Information
GroupFIN7

FIN7 has compiled a list of victims by filtering companies by revenue using Zoominfo, which is a service that provides business information.

T1591.004
Identify Roles
GroupFIN7

FIN7 has identified IT staff and employees who had higher levels of administrative rights.

T1608.001
Upload Malware
GroupFIN7

FIN7 has staged legitimate software, that was trojanized to contain an Atera agent installer, on Amazon S3. FIN7 has also used an open directory web server as a staging server for payloads and other tools, such as OpenSSH and 7zip.

T1608.004
Drive-by Target
GroupFIN7

FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products.

T1608.005
Link Target
GroupFIN7

FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable.

T1620
Reflective Code Loading
GroupFIN7

FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`.

T1674
Input Injection
GroupFIN7

FIN7 has used malicious USBs to emulate keystrokes to launch PowerShell to download and execute malware from the adversary's server.

T1686
Disable or Modify System Firewall
GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.