ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0061×

36 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN8

FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).

T1016.001
Internet Connection Discovery
GroupFIN8

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

T1018
Remote System Discovery
GroupFIN8

FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.

T1021.001
Remote Desktop Protocol
GroupFIN8

FIN8 has used RDP for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupFIN8

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1033
System Owner/User Discovery
GroupFIN8

FIN8 has executed the command `quser` to display the session details of a compromised machine.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

T1053.005
Scheduled Task
GroupFIN8

FIN8 has used scheduled tasks to maintain RDP backdoors.

T1055.004
Asynchronous Procedure Call
GroupFIN8

FIN8 has injected malicious code into a new svchost.exe process.

T1059.001
PowerShell
GroupFIN8

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

T1071.001
Web Protocols
GroupFIN8

FIN8 has used HTTPS for command and control.

T1074.002
Remote Data Staging
GroupFIN8

FIN8 aggregates staged data from a network into a single location.

T1078
Valid Accounts
GroupFIN8

FIN8 has used valid accounts for persistence and lateral movement.

T1082
System Information Discovery
GroupFIN8

FIN8 has used PowerShell Scripts to check the architecture of a compromised machine before the selection of a 32-bit or 64-bit version of a malicious .NET loader.

T1102
Web Service
GroupFIN8

FIN8 has used sslip.io, a free IP to domain mapping service that also makes SSL certificate generation easier for traffic encryption, as part of their command and control.

T1105
Ingress Tool Transfer
GroupFIN8

FIN8 has used remote code execution to download subsequent payloads.

T1112
Modify Registry
GroupFIN8

FIN8 has deleted Registry keys during post compromise cleanup activities.

T1134.001
Token Impersonation/Theft
GroupFIN8

FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token.

T1204.001
Malicious Link
GroupFIN8

FIN8 has used emails with malicious links to lure victims into installing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1482
Domain Trust Discovery
GroupFIN8

FIN8 has retrieved a list of trusted domains by using nltest.exe /domain_trusts.

T1486
Data Encrypted for Impact
GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

T1518.001
Security Software Discovery
GroupFIN8

FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.

T1546.003
Windows Management Instrumentation Event Subscription
GroupFIN8

FIN8 has used WMI event subscriptions for persistence.

T1560.001
Archive via Utility
GroupFIN8

FIN8 has used RAR to compress collected data before exfiltration.

T1566.001
Spearphishing Attachment
GroupFIN8

FIN8 has distributed targeted emails containing Word documents with embedded malicious macros.

T1566.002
Spearphishing Link
GroupFIN8

FIN8 has distributed targeted emails containing links to malicious documents with embedded macros.

T1573.002
Asymmetric Cryptography
GroupFIN8

FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure.

T1588.002
Tool
GroupFIN8

FIN8 has used open-source tools such as Impacket for targeting efforts.

T1588.003
Code Signing Certificates
GroupFIN8

FIN8 has used an expired open-source X.509 certificate for testing in the OpenSSL repository, to connect to actor-controlled C2 servers.

T1685.005
Clear Windows Event Logs
GroupFIN8

FIN8 has cleared logs during post compromise cleanup activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.