Real-world descriptions of how a group, tool or campaign used a technique.
78 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1005 Data from Local System |
GroupMagic Hound | Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016.001 Internet Connection Discovery |
GroupMagic Hound | Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| T1016.002 Wi-Fi Discovery |
GroupMagic Hound | Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1018 Remote System Discovery |
GroupMagic Hound | Magic Hound has used Ping for discovery on targeted networks. |
| T1021.001 Remote Desktop Protocol |
GroupMagic Hound | Magic Hound has used Remote Desktop Services to copy tools on targeted systems. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.013 Encrypted/Encoded File |
GroupMagic Hound | Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1036.004 Masquerade Task or Service |
GroupMagic Hound | Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.010 Masquerade Account Name |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1046 Network Service Discovery |
GroupMagic Hound | Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning. |
| T1047 Windows Management Instrumentation |
GroupMagic Hound | Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
| T1049 System Network Connections Discovery |
GroupMagic Hound | Magic Hound has used quser.exe to identify existing RDP connections. |
| T1053.005 Scheduled Task |
GroupMagic Hound | Magic Hound has used scheduled tasks to establish persistence and execution. |
| T1056.001 Keylogging |
GroupMagic Hound | Magic Hound malware is capable of keylogging. |
| T1057 Process Discovery |
GroupMagic Hound | Magic Hound malware can list running processes. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1059.003 Windows Command Shell |
GroupMagic Hound | Magic Hound has used the command-line interface for code execution. |
| T1059.005 Visual Basic |
GroupMagic Hound | Magic Hound malware has used VBS scripts for execution. |
| T1070.003 Clear Command History |
GroupMagic Hound | Magic Hound has removed mailbox export requests from compromised Exchange servers. |
| T1070.004 File Deletion |
GroupMagic Hound | Magic Hound has deleted and overwrote files to cover tracks. |
| T1071 Application Layer Protocol |
GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| T1071.001 Web Protocols |
GroupMagic Hound | Magic Hound has used HTTP for C2. |
| T1078.001 Default Accounts |
GroupMagic Hound | Magic Hound enabled and used the default system managed account, DefaultAccount, via `"powershell.exe" /c net user DefaultAccount /active:yes` to connect to a targeted Exchange server over RDP. |
| T1078.002 Domain Accounts |
GroupMagic Hound | Magic Hound has used domain administrator accounts after dumping LSASS process memory. |
| T1082 System Information Discovery |
GroupMagic Hound | Magic Hound malware has used a PowerShell command to check the victim system architecture to determine if it is an x64 machine. Other malware has obtained the OS version, UUID, and computer/host name to send to the C2 server. |
| T1083 File and Directory Discovery |
GroupMagic Hound | Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents. |
| T1087.003 Email Account |
GroupMagic Hound | Magic Hound has used Powershell to discover email accounts. |
| T1090 Proxy |
GroupMagic Hound | Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic. |
| T1098.002 Additional Email Delegate Permissions |
GroupMagic Hound | Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations. |
| T1098.007 Additional Local or Domain Groups |
GroupMagic Hound | Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups. |
| T1102.002 Bidirectional Communication |
GroupMagic Hound | Magic Hound malware can use a SOAP Web service to communicate with its C2 server. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1112 Modify Registry |
GroupMagic Hound | Magic Hound has modified Registry settings for security tools. |
| T1113 Screen Capture |
GroupMagic Hound | Magic Hound malware can take a screenshot and upload the file to its C2 server. |
| T1114 Email Collection |
GroupMagic Hound | Magic Hound has compromised email credentials in order to steal sensitive data. |
| T1114.001 Local Email Collection |
GroupMagic Hound | Magic Hound has collected .PST archives. |
| T1114.002 Remote Email Collection |
GroupMagic Hound | Magic Hound has exported emails from compromised Exchange servers including through use of the cmdlet `New-MailboxExportRequest.` |
| T1136.001 Local Account |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1189 Drive-by Compromise |
GroupMagic Hound | Magic Hound has conducted watering-hole attacks through media and magazine websites. |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1204.001 Malicious Link |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious links embedded in emails. |
| T1204.002 Malicious File |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious email attachments. |
| T1218.011 Rundll32 |
GroupMagic Hound | Magic Hound has used rundll32.exe to execute MiniDump from comsvcs.dll when dumping LSASS memory. |
| T1482 Domain Trust Discovery |
GroupMagic Hound | Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships. |
| T1486 Data Encrypted for Impact |
GroupMagic Hound | Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.