Real-world descriptions of how a group, tool or campaign used a technique.
70 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings. |
| T1005 Data from Local System |
GroupGamaredon Group | Gamaredon Group has collected files from infected systems and uploaded them to a C2 server. |
| T1012 Query Registry |
GroupGamaredon Group | Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. |
| T1016.001 Internet Connection Discovery |
GroupGamaredon Group | Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status. |
| T1020 Automated Exfiltration |
GroupGamaredon Group | Gamaredon Group has used modules that automatically upload gathered documents to the C2 server. |
| T1021.005 VNC |
GroupGamaredon Group | Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1025 Data from Removable Media |
GroupGamaredon Group | A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| T1027 Obfuscated Files or Information |
GroupGamaredon Group | Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file. |
| T1027.004 Compile After Delivery |
GroupGamaredon Group | Gamaredon Group has compiled the source code for a downloader directly on the infected system using the built-in |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1027.012 LNK Icon Smuggling |
GroupGamaredon Group | Gamaredon Group has used LNK files to hide malicious scripts for execution. |
| T1027.015 Compression |
GroupGamaredon Group | Gamaredon Group has delivered malicious payloads within compressed archives and zip files. |
| T1027.016 Junk Code Insertion |
GroupGamaredon Group | Gamaredon Group has obfuscated .NET executables by inserting junk code. |
| T1033 System Owner/User Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's username to send to a C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupGamaredon Group | Gamaredon Group has used legitimate process names to hide malware including |
| T1039 Data from Network Shared Drive |
GroupGamaredon Group | Gamaredon Group malware has collected Microsoft Office documents from mapped network drives. |
| T1041 Exfiltration Over C2 Channel |
GroupGamaredon Group | A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1053.005 Scheduled Task |
GroupGamaredon Group | Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed. |
| T1055 Process Injection |
GroupGamaredon Group | Gamaredon Group has injected Remcos into explorer.exe. |
| T1057 Process Discovery |
GroupGamaredon Group | Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1059.003 Windows Command Shell |
GroupGamaredon Group | Gamaredon Group has used various batch scripts to establish C2 and download additional files. Gamaredon Group's backdoor malware has also been written to a batch file. |
| T1059.005 Visual Basic |
GroupGamaredon Group | Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe. |
| T1070.004 File Deletion |
GroupGamaredon Group | Gamaredon Group tools can delete files used during an operation. |
| T1071.001 Web Protocols |
GroupGamaredon Group | Gamaredon Group has used HTTP and HTTPS for C2 communications. |
| T1080 Taint Shared Content |
GroupGamaredon Group | Gamaredon Group has injected malicious macros into all Word and Excel documents on mapped network drives. |
| T1082 System Information Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's computer name and drive serial numbers to send to a C2 server. |
| T1083 File and Directory Discovery |
GroupGamaredon Group | Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host. |
| T1090 Proxy |
GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| T1090.003 Multi-hop Proxy |
GroupGamaredon Group | Gamaredon Group has used Tor for C2 traffic. |
| T1091 Replication Through Removable Media |
GroupGamaredon Group | Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host. |
| T1095 Non-Application Layer Protocol |
GroupGamaredon Group | Gamaredon Group has used SOCKS5 over port 9050 for C2 communication. |
| T1102 Web Service |
GroupGamaredon Group | Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system. |
| T1102.002 Bidirectional Communication |
GroupGamaredon Group | Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain. |
| T1102.003 One-Way Communication |
GroupGamaredon Group | Gamaredon Group has used Telegram Messenger content to discover the IP address for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1106 Native API |
GroupGamaredon Group | Gamaredon Group malware has used |
| T1112 Modify Registry |
GroupGamaredon Group | Gamaredon Group has removed security settings for VBA macro execution by changing registry values |
| T1113 Screen Capture |
GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| T1119 Automated Collection |
GroupGamaredon Group | Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents. |
| T1120 Peripheral Device Discovery |
GroupGamaredon Group | Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives. |
| T1137 Office Application Startup |
GroupGamaredon Group | Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the |
| T1140 Deobfuscate/Decode Files or Information |
GroupGamaredon Group | Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications. |
| T1204.001 Malicious Link |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on a link pointing to a malicious HTML file leading to follow-on malicious content. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1218.005 Mshta |
GroupGamaredon Group | Gamaredon Group has used `mshta.exe` to execute malicious files. |
| T1218.011 Rundll32 |
GroupGamaredon Group | Gamaredon Group malware has used rundll32 to launch additional malicious components. |
| T1221 Template Injection |
GroupGamaredon Group | Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems. |
| T1480 Execution Guardrails |
GroupGamaredon Group | Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.