ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0050×

78 examples

TechniqueUsed byProcedure example
T1218.011
Rundll32
GroupAPT32

APT32 malware has used rundll32.exe to execute an initial infection process.

T1222.002
Linux and Mac Permissions
GroupAPT32

APT32's macOS backdoor changes the permission of the file it wants to execute to 755.

T1505.003
Web Shell
GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

T1543.003
Windows Service
GroupAPT32

APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT32

APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.

T1550.002
Pass the Hash
GroupAPT32

APT32 has used pass the hash for lateral movement.

T1550.003
Pass the Ticket
GroupAPT32

APT32 successfully gained remote access by using pass the ticket.

T1552.002
Credentials in Registry
GroupAPT32

APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry.

T1560
Archive Collected Data
GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

T1564.001
Hidden Files and Directories
GroupAPT32

APT32's macOS backdoor hides the clientID file via a chflags function.

T1564.003
Hidden Window
GroupAPT32

APT32 has used the WindowStyle parameter to conceal PowerShell windows.

T1564.004
NTFS File Attributes
GroupAPT32

APT32 used NTFS alternate data streams to hide their payloads.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1566.002
Spearphishing Link
GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

T1569.002
Service Execution
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

T1570
Lateral Tool Transfer
GroupAPT32

APT32 has deployed tools after moving laterally using administrative accounts.

T1571
Non-Standard Port
GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

T1574.001
DLL
GroupAPT32

APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder).

T1583.001
Domains
GroupAPT32

APT32 has set up and operated websites to gather information and deliver malware.

T1583.006
Web Services
GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1585.001
Social Media Accounts
GroupAPT32

APT32 has set up Facebook pages in tandem with fake websites.

T1588.002
Tool
GroupAPT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.

T1589
Gather Victim Identity Information
GroupAPT32

APT32 has conducted targeted surveillance against activists and bloggers.

T1589.002
Email Addresses
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

T1598.003
Spearphishing Link
GroupAPT32

APT32 has used malicious links to direct users to web pages designed to harvest credentials.

T1608.001
Upload Malware
GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

T1608.004
Drive-by Target
GroupAPT32

APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update.

T1685.005
Clear Windows Event Logs
GroupAPT32

APT32 has cleared select event log entries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.