Real-world descriptions of how a group, tool or campaign used a technique.
70 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1491.001 Internal Defacement |
GroupGamaredon Group | Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access. |
| T1497.001 System Checks |
GroupGamaredon Group | Gamaredon Group has checked existing conditions, such as geographic location, device type, or system specification, before the victim is sent a malicious Word document. |
| T1518.001 Security Software Discovery |
GroupGamaredon Group | Gamaredon Group has used PowerShell scripts to identify security software on the victim machine. |
| T1534 Internal Spearphishing |
GroupGamaredon Group | Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupGamaredon Group | Gamaredon Group tools have registered Run keys in the registry to give malicious VBS files persistence. |
| T1559.001 Component Object Model |
GroupGamaredon Group | Gamaredon Group malware can insert malicious macros into documents using a |
| T1561.001 Disk Content Wipe |
GroupGamaredon Group | Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles. |
| T1564.003 Hidden Window |
GroupGamaredon Group | Gamaredon Group has used |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1568 Dynamic Resolution |
GroupGamaredon Group | Gamaredon Group has incorporated dynamic DNS domains in its infrastructure. |
| T1568.001 Fast Flux DNS |
GroupGamaredon Group | Gamaredon Group has used fast flux DNS to mask their command and control channel behind rotating IP addresses. Additionally, Gamaredon Group has used a low-frequency variant of the single-flux method. |
| T1571 Non-Standard Port |
GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
| T1583.003 Virtual Private Server |
GroupGamaredon Group | Gamaredon Group has used VPS hosting providers for infrastructure outside of Russia. |
| T1583.006 Web Services |
GroupGamaredon Group | Gamaredon Group has used Cloudflare’s TryClouldflare service to obtain C2 nodes. |
| T1587.003 Digital Certificates |
GroupGamaredon Group | Gamaredon Group has used the same TLS certificate across its infrastructure. |
| T1588.002 Tool |
GroupGamaredon Group | Gamaredon Group has used various legitimate tools, such as `mshta.exe` and Reg, and services during operations. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
| T1620 Reflective Code Loading |
GroupGamaredon Group | Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2. |
| T1685 Disable or Modify Tools |
GroupGamaredon Group | Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.