Real-world descriptions of how a group, tool or campaign used a technique.
76 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1203 Exploitation for Client Execution |
GroupOilRig | OilRig has exploited CVE-2024-30088 to run arbitrary code in the context of `SYSTEM`. |
| T1204.001 Malicious Link |
GroupOilRig | OilRig has delivered malicious links to achieve execution on the target system. |
| T1204.002 Malicious File |
GroupOilRig | OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system. |
| T1218.001 Compiled HTML File |
GroupOilRig | OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim. |
| T1219 Remote Access Tools |
GroupOilRig | OilRig has incorporated remote monitoring and management (RMM) tools into their operations including ngrok. |
| T1497.001 System Checks |
GroupOilRig | OilRig has used macros to verify if a mouse is connected to a compromised machine. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1543.003 Windows Service |
GroupOilRig | OilRig has used a compromised Domain Controller to create a service on a remote host. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1553.002 Code Signing |
GroupOilRig | OilRig has signed its malware with stolen certificates. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1555.004 Windows Credential Manager |
GroupOilRig | OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager. |
| T1556.002 Password Filter DLL |
GroupOilRig | OilRig has registered a password filter DLL in order to drop malware. |
| T1566.001 Spearphishing Attachment |
GroupOilRig | OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts. |
| T1566.002 Spearphishing Link |
GroupOilRig | OilRig has sent spearphising emails with malicious links to potential victims. |
| T1566.003 Spearphishing via Service |
GroupOilRig | OilRig has used LinkedIn to send spearphishing links. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupOilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers. |
| T1583.001 Domains |
GroupOilRig | OilRig has set up fake VPN portals, conference sign ups, and job application websites to target victims. |
| T1586.002 Email Accounts |
GroupOilRig | OilRig has compromised email accounts to send phishing emails. |
| T1587.001 Malware |
GroupOilRig | OilRig actively developed and used a series of downloaders during 2022. |
| T1588.002 Tool |
GroupOilRig | OilRig has made use of the publicly available tools including Plink and Mimikatz. |
| T1588.003 Code Signing Certificates |
GroupOilRig | OilRig has obtained stolen code signing certificates to digitally sign malware. |
| T1608.001 Upload Malware |
GroupOilRig | OilRig has hosted malware on fake websites designed to target specific audiences. |
| T1686.003 Windows Host Firewall |
GroupOilRig | OilRig has modified Windows firewall rules to enable remote access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.