ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0049×

76 examples

TechniqueUsed byProcedure example
T1203
Exploitation for Client Execution
GroupOilRig

OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of `SYSTEM`.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1218.001
Compiled HTML File
GroupOilRig

OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim.

T1219
Remote Access Tools
GroupOilRig

OilRig has incorporated remote monitoring and management (RMM) tools into their operations including ngrok.

T1497.001
System Checks
GroupOilRig

OilRig has used macros to verify if a mouse is connected to a compromised machine.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1543.003
Windows Service
GroupOilRig

OilRig has used a compromised Domain Controller to create a service on a remote host.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1553.002
Code Signing
GroupOilRig

OilRig has signed its malware with stolen certificates.

T1555
Credentials from Password Stores
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1555.004
Windows Credential Manager
GroupOilRig

OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager.

T1556.002
Password Filter DLL
GroupOilRig

OilRig has registered a password filter DLL in order to drop malware.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

T1566.002
Spearphishing Link
GroupOilRig

OilRig has sent spearphising emails with malicious links to potential victims.

T1566.003
Spearphishing via Service
GroupOilRig

OilRig has used LinkedIn to send spearphishing links.

T1572
Protocol Tunneling
GroupOilRig

OilRig has used the Plink utility and other tools to create tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupOilRig

OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers.

T1583.001
Domains
GroupOilRig

OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims.

T1586.002
Email Accounts
GroupOilRig

OilRig has compromised email accounts to send phishing emails.

T1587.001
Malware
GroupOilRig

OilRig actively developed and used a series of downloaders during 2022.

T1588.002
Tool
GroupOilRig

OilRig has made use of the publicly available tools including Plink and Mimikatz.

T1588.003
Code Signing Certificates
GroupOilRig

OilRig has obtained stolen code signing certificates to digitally sign malware.

T1608.001
Upload Malware
GroupOilRig

OilRig has hosted malware on fake websites designed to target specific audiences.

T1686.003
Windows Host Firewall
GroupOilRig

OilRig has modified Windows firewall rules to enable remote access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.