Real-world descriptions of how a group, tool or campaign used a technique.
78 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1560.001 Archive via Utility |
GroupMagic Hound | Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders. |
| T1564.003 Hidden Window |
GroupMagic Hound | Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window. |
| T1566.002 Spearphishing Link |
GroupMagic Hound | Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy. |
| T1566.003 Spearphishing via Service |
GroupMagic Hound | Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims. |
| T1567 Exfiltration Over Web Service |
GroupMagic Hound | Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices. |
| T1570 Lateral Tool Transfer |
GroupMagic Hound | Magic Hound has copied tools within a compromised network using RDP. |
| T1571 Non-Standard Port |
GroupMagic Hound | Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP. |
| T1572 Protocol Tunneling |
GroupMagic Hound | Magic Hound has used Plink to tunnel RDP over SSH. |
| T1573 Encrypted Channel |
GroupMagic Hound | Magic Hound has used an encrypted http proxy in C2 communications. |
| T1583.001 Domains |
GroupMagic Hound | Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks. |
| T1583.006 Web Services |
GroupMagic Hound | Magic Hound has acquired Amazon S3 buckets to use in C2. |
| T1584.001 Domains |
GroupMagic Hound | Magic Hound has used compromised domains to host links targeted to specific phishing victims. |
| T1585.001 Social Media Accounts |
GroupMagic Hound | Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links. |
| T1585.002 Email Accounts |
GroupMagic Hound | Magic Hound has established email accounts using fake personas for spearphishing operations. |
| T1586.002 Email Accounts |
GroupMagic Hound | Magic Hound has compromised personal email accounts through the use of legitimate credentials and gathered additional victim information. |
| T1588.002 Tool |
GroupMagic Hound | Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink. |
| T1589 Gather Victim Identity Information |
GroupMagic Hound | Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations. |
| T1589.001 Credentials |
GroupMagic Hound | Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel. |
| T1589.002 Email Addresses |
GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
| T1590.005 IP Addresses |
GroupMagic Hound | Magic Hound has captured the IP addresses of visitors to their phishing sites. |
| T1591.001 Determine Physical Locations |
GroupMagic Hound | Magic Hound has collected location information from visitors to their phishing sites. |
| T1592.002 Software |
GroupMagic Hound | Magic Hound has captured the user-agent strings from visitors to their phishing sites. |
| T1595.002 Vulnerability Scanning |
GroupMagic Hound | Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
| T1685 Disable or Modify Tools |
GroupMagic Hound | Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads. |
| T1685.001 Disable or Modify Windows Event Log |
GroupMagic Hound | Magic Hound has executed scripts to disable the event log service. |
| T1686.003 Windows Host Firewall |
GroupMagic Hound | Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.