Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFIN8 | FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE). |
| T1016.001 Internet Connection Discovery |
GroupFIN8 | FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| T1018 Remote System Discovery |
GroupFIN8 | FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used |
| T1021.001 Remote Desktop Protocol |
GroupFIN8 | FIN8 has used RDP for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN8 | FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1033 System Owner/User Discovery |
GroupFIN8 | FIN8 has executed the command `quser` to display the session details of a compromised machine. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN8 | FIN8 has used FTP to exfiltrate collected data. |
| T1053.005 Scheduled Task |
GroupFIN8 | FIN8 has used scheduled tasks to maintain RDP backdoors. |
| T1055.004 Asynchronous Procedure Call |
GroupFIN8 | FIN8 has injected malicious code into a new svchost.exe process. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
| T1071.001 Web Protocols |
GroupFIN8 | FIN8 has used HTTPS for command and control. |
| T1074.002 Remote Data Staging |
GroupFIN8 | FIN8 aggregates staged data from a network into a single location. |
| T1078 Valid Accounts |
GroupFIN8 | FIN8 has used valid accounts for persistence and lateral movement. |
| T1082 System Information Discovery |
GroupFIN8 | FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader. |
| T1102 Web Service |
GroupFIN8 | FIN8 has used |
| T1105 Ingress Tool Transfer |
GroupFIN8 | FIN8 has used remote code execution to download subsequent payloads. |
| T1112 Modify Registry |
GroupFIN8 | FIN8 has deleted Registry keys during post compromise cleanup activities. |
| T1134.001 Token Impersonation/Theft |
GroupFIN8 | FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1482 Domain Trust Discovery |
GroupFIN8 | FIN8 has retrieved a list of trusted domains by using |
| T1486 Data Encrypted for Impact |
GroupFIN8 | FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks. |
| T1518.001 Security Software Discovery |
GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupFIN8 | FIN8 has used WMI event subscriptions for persistence. |
| T1560.001 Archive via Utility |
GroupFIN8 | FIN8 has used RAR to compress collected data before exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
| T1566.002 Spearphishing Link |
GroupFIN8 | FIN8 has distributed targeted emails containing links to malicious documents with embedded macros. |
| T1573.002 Asymmetric Cryptography |
GroupFIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. |
| T1588.002 Tool |
GroupFIN8 | FIN8 has used open-source tools such as Impacket for targeting efforts. |
| T1588.003 Code Signing Certificates |
GroupFIN8 | FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers. |
| T1685.005 Clear Windows Event Logs |
GroupFIN8 | FIN8 has cleared logs during post compromise cleanup activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.