ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0059×

78 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1564.003
Hidden Window
GroupMagic Hound

Magic Hound malware has a function to determine whether the C2 server wishes to execute the newly dropped file in a hidden window.

T1566.002
Spearphishing Link
GroupMagic Hound

Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy.

T1566.003
Spearphishing via Service
GroupMagic Hound

Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims.

T1567
Exfiltration Over Web Service
GroupMagic Hound

Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices.

T1570
Lateral Tool Transfer
GroupMagic Hound

Magic Hound has copied tools within a compromised network using RDP.

T1571
Non-Standard Port
GroupMagic Hound

Magic Hound malware has communicated with its C2 server over TCP ports 4443 and 10151 using HTTP.

T1572
Protocol Tunneling
GroupMagic Hound

Magic Hound has used Plink to tunnel RDP over SSH.

T1573
Encrypted Channel
GroupMagic Hound

Magic Hound has used an encrypted http proxy in C2 communications.

T1583.001
Domains
GroupMagic Hound

Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks.

T1583.006
Web Services
GroupMagic Hound

Magic Hound has acquired Amazon S3 buckets to use in C2.

T1584.001
Domains
GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

T1585.001
Social Media Accounts
GroupMagic Hound

Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links.

T1585.002
Email Accounts
GroupMagic Hound

Magic Hound has established email accounts using fake personas for spearphishing operations.

T1586.002
Email Accounts
GroupMagic Hound

Magic Hound has compromised personal email accounts through the use of legitimate credentials and gathered additional victim information.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1589
Gather Victim Identity Information
GroupMagic Hound

Magic Hound has acquired mobile phone numbers of potential targets, possibly for mobile malware or additional phishing operations.

T1589.001
Credentials
GroupMagic Hound

Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel.

T1589.002
Email Addresses
GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

T1590.005
IP Addresses
GroupMagic Hound

Magic Hound has captured the IP addresses of visitors to their phishing sites.

T1591.001
Determine Physical Locations
GroupMagic Hound

Magic Hound has collected location information from visitors to their phishing sites.

T1592.002
Software
GroupMagic Hound

Magic Hound has captured the user-agent strings from visitors to their phishing sites.

T1595.002
Vulnerability Scanning
GroupMagic Hound

Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs.

T1598.003
Spearphishing Link
GroupMagic Hound

Magic Hound has used SMS and email messages with links designed to steal credentials or track victims.

T1685
Disable or Modify Tools
GroupMagic Hound

Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads.

T1685.001
Disable or Modify Windows Event Log
GroupMagic Hound

Magic Hound has executed scripts to disable the event log service.

T1686.003
Windows Host Firewall
GroupMagic Hound

Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.