ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0047×

70 examples

TechniqueUsed byProcedure example
T1001
Data Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings.

T1005
Data from Local System
GroupGamaredon Group

Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.

T1012
Query Registry
GroupGamaredon Group

Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses.

T1016.001
Internet Connection Discovery
GroupGamaredon Group

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

T1020
Automated Exfiltration
GroupGamaredon Group

Gamaredon Group has used modules that automatically upload gathered documents to the C2 server.

T1021.005
VNC
GroupGamaredon Group

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

T1025
Data from Removable Media
GroupGamaredon Group

A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives.

T1027
Obfuscated Files or Information
GroupGamaredon Group

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027.004
Compile After Delivery
GroupGamaredon Group

Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in Microsoft.CSharp.CSharpCodeProvider class.

T1027.010
Command Obfuscation
GroupGamaredon Group

Gamaredon Group has used obfuscated or encrypted scripts.

T1027.012
LNK Icon Smuggling
GroupGamaredon Group

Gamaredon Group has used LNK files to hide malicious scripts for execution.

T1027.015
Compression
GroupGamaredon Group

Gamaredon Group has delivered malicious payloads within compressed archives and zip files.

T1027.016
Junk Code Insertion
GroupGamaredon Group

Gamaredon Group has obfuscated .NET executables by inserting junk code.

T1033
System Owner/User Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's username to send to a C2 server.

T1036.005
Match Legitimate Resource Name or Location
GroupGamaredon Group

Gamaredon Group has used legitimate process names to hide malware including svchosst. Additionally, Gamaredon Group disguised malicious ZIP archives as Office documents that are related to the invasion.

T1039
Data from Network Shared Drive
GroupGamaredon Group

Gamaredon Group malware has collected Microsoft Office documents from mapped network drives.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1053.005
Scheduled Task
GroupGamaredon Group

Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed.

T1055
Process Injection
GroupGamaredon Group

Gamaredon Group has injected Remcos into explorer.exe.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1059.001
PowerShell
GroupGamaredon Group

Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload.

T1059.003
Windows Command Shell
GroupGamaredon Group

Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file.

T1059.005
Visual Basic
GroupGamaredon Group

Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe.

T1070.004
File Deletion
GroupGamaredon Group

Gamaredon Group tools can delete files used during an operation.

T1071.001
Web Protocols
GroupGamaredon Group

Gamaredon Group has used HTTP and HTTPS for C2 communications.

T1080
Taint Shared Content
GroupGamaredon Group

Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives.

T1082
System Information Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server.

T1083
File and Directory Discovery
GroupGamaredon Group

Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host.

T1090
Proxy
GroupGamaredon Group

Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic.

T1090.003
Multi-hop Proxy
GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

T1091
Replication Through Removable Media
GroupGamaredon Group

Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host.

T1095
Non-Application Layer Protocol
GroupGamaredon Group

Gamaredon Group has used SOCKS5 over port 9050 for C2 communication.

T1102
Web Service
GroupGamaredon Group

Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system.

T1102.002
Bidirectional Communication
GroupGamaredon Group

Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain.

T1102.003
One-Way Communication
GroupGamaredon Group

Gamaredon Group has used Telegram Messenger content to discover the IP address for C2 communications.

T1105
Ingress Tool Transfer
GroupGamaredon Group

Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments.

T1106
Native API
GroupGamaredon Group

Gamaredon Group malware has used CreateProcess to launch additional malicious components.

T1112
Modify Registry
GroupGamaredon Group

Gamaredon Group has removed security settings for VBA macro execution by changing registry values HKCU\Software\Microsoft\Office\<version>\<product>\Security\VBAWarnings and HKCU\Software\Microsoft\Office\<version>\<product>\Security\AccessVBOM. Gamaredon Group has also modified Registry keys to hide folders and system files and to add the C2 address under `HKEY_CURRENT_USER\Console\WindowsUpdate`.

T1113
Screen Capture
GroupGamaredon Group

Gamaredon Group's malware can take screenshots of the compromised computer every minute.

T1119
Automated Collection
GroupGamaredon Group

Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents.

T1120
Peripheral Device Discovery
GroupGamaredon Group

Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives.

T1137
Office Application Startup
GroupGamaredon Group

Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the /altvba option, once the Application.Startup event is received.

T1140
Deobfuscate/Decode Files or Information
GroupGamaredon Group

Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications.

T1204.001
Malicious Link
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content.

T1204.002
Malicious File
GroupGamaredon Group

Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files.

T1218.005
Mshta
GroupGamaredon Group

Gamaredon Group has used `mshta.exe` to execute malicious files.

T1218.011
Rundll32
GroupGamaredon Group

Gamaredon Group malware has used rundll32 to launch additional malicious components.

T1221
Template Injection
GroupGamaredon Group

Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems.

T1480
Execution Guardrails
GroupGamaredon Group

Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.