Real-world descriptions of how a group, tool or campaign used a technique.
78 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.011 Rundll32 |
GroupAPT32 | APT32 malware has used rundll32.exe to execute an initial infection process. |
| T1222.002 Linux and Mac Permissions |
GroupAPT32 | APT32's macOS backdoor changes the permission of the file it wants to execute to 755. |
| T1505.003 Web Shell |
GroupAPT32 | APT32 has used Web shells to maintain access to victim websites. |
| T1543.003 Windows Service |
GroupAPT32 | APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT32 | APT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly. |
| T1550.002 Pass the Hash |
GroupAPT32 | APT32 has used pass the hash for lateral movement. |
| T1550.003 Pass the Ticket |
GroupAPT32 | APT32 successfully gained remote access by using pass the ticket. |
| T1552.002 Credentials in Registry |
GroupAPT32 | APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry. |
| T1560 Archive Collected Data |
GroupAPT32 | APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration. |
| T1564.001 Hidden Files and Directories |
GroupAPT32 | APT32's macOS backdoor hides the clientID file via a chflags function. |
| T1564.003 Hidden Window |
GroupAPT32 | APT32 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1564.004 NTFS File Attributes |
GroupAPT32 | APT32 used NTFS alternate data streams to hide their payloads. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1569.002 Service Execution |
GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| T1570 Lateral Tool Transfer |
GroupAPT32 | APT32 has deployed tools after moving laterally using administrative accounts. |
| T1571 Non-Standard Port |
GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| T1574.001 DLL |
GroupAPT32 | APT32 ran legitimately-signed executables from Symantec and McAfee which load a malicious DLL. The group also side-loads its backdoor by dropping a library and a legitimate, signed executable (AcroTranscoder). |
| T1583.001 Domains |
GroupAPT32 | APT32 has set up and operated websites to gather information and deliver malware. |
| T1583.006 Web Services |
GroupAPT32 | APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1585.001 Social Media Accounts |
GroupAPT32 | APT32 has set up Facebook pages in tandem with fake websites. |
| T1588.002 Tool |
GroupAPT32 | APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub. |
| T1589 Gather Victim Identity Information |
GroupAPT32 | APT32 has conducted targeted surveillance against activists and bloggers. |
| T1589.002 Email Addresses |
GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
| T1598.003 Spearphishing Link |
GroupAPT32 | APT32 has used malicious links to direct users to web pages designed to harvest credentials. |
| T1608.001 Upload Malware |
GroupAPT32 | APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting. |
| T1608.004 Drive-by Target |
GroupAPT32 | APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update. |
| T1685.005 Clear Windows Event Logs |
GroupAPT32 | APT32 has cleared select event log entries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.