ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0047×

70 examples

TechniqueUsed byProcedure example
T1491.001
Internal Defacement
GroupGamaredon Group

Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access.

T1497.001
System Checks
GroupGamaredon Group

Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document.

T1518.001
Security Software Discovery
GroupGamaredon Group

Gamaredon Group has used PowerShell scripts to identify security software on the victim machine.

T1534
Internal Spearphishing
GroupGamaredon Group

Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization.

T1547.001
Registry Run Keys / Startup Folder
GroupGamaredon Group

Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence.

T1559.001
Component Object Model
GroupGamaredon Group

Gamaredon Group malware can insert malicious macros into documents using a Microsoft.Office.Interop object.

T1561.001
Disk Content Wipe
GroupGamaredon Group

Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles.

T1564.003
Hidden Window
GroupGamaredon Group

Gamaredon Group has used hidcon to run batch files in a hidden console window. Gamaredon Group has also executed PowerShell in a hidden window.

T1566.001
Spearphishing Attachment
GroupGamaredon Group

Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives.

T1568
Dynamic Resolution
GroupGamaredon Group

Gamaredon Group has incorporated dynamic DNS domains in its infrastructure.

T1568.001
Fast Flux DNS
GroupGamaredon Group

Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method.

T1571
Non-Standard Port
GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

T1583.001
Domains
GroupGamaredon Group

Gamaredon Group has registered multiple domains to facilitate payload staging and C2.

T1583.003
Virtual Private Server
GroupGamaredon Group

Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia.

T1583.006
Web Services
GroupGamaredon Group

Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes.

T1587.003
Digital Certificates
GroupGamaredon Group

Gamaredon Group has used the same TLS certificate across its infrastructure.

T1588.002
Tool
GroupGamaredon Group

Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations.

T1608.001
Upload Malware
GroupGamaredon Group

Gamaredon Group has registered domains to stage payloads.

T1620
Reflective Code Loading
GroupGamaredon Group

Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2.

T1685
Disable or Modify Tools
GroupGamaredon Group

Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.