ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0065×

50 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

T1003.001
LSASS Memory
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE.

T1021.001
Remote Desktop Protocol
GroupLeviathan

Leviathan has targeted RDP credentials and used it to move through the victim environment.

T1021.004
SSH
GroupLeviathan

Leviathan used ssh for internal reconnaissance.

T1027.001
Binary Padding
GroupLeviathan

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

T1027.003
Steganography
GroupLeviathan

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1027.013
Encrypted/Encoded File
GroupLeviathan

Leviathan has obfuscated code using base64.

T1027.015
Compression
GroupLeviathan

Leviathan has obfuscated code using gzip compression.

T1041
Exfiltration Over C2 Channel
GroupLeviathan

Leviathan has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation
GroupLeviathan

Leviathan has used WMI for execution.

T1055.001
Dynamic-link Library Injection
GroupLeviathan

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1059.005
Visual Basic
GroupLeviathan

Leviathan has used VBScript.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.002
Remote Data Staging
GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

T1078
Valid Accounts
GroupLeviathan

Leviathan has obtained valid accounts to gain initial access.

T1090.003
Multi-hop Proxy
GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

T1102.003
One-Way Communication
GroupLeviathan

Leviathan has received C2 instructions from user profiles created on legitimate websites such as Github and TechNet.

T1105
Ingress Tool Transfer
GroupLeviathan

Leviathan has downloaded additional scripts and files from adversary-controlled servers.

T1133
External Remote Services
GroupLeviathan

Leviathan has used external remote services such as virtual private networks (VPN) to gain initial access.

T1140
Deobfuscate/Decode Files or Information
GroupLeviathan

Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors.

T1189
Drive-by Compromise
GroupLeviathan

Leviathan has infected victims using watering holes.

T1190
Exploit Public-Facing Application
GroupLeviathan

Leviathan has used exploits against publicly-disclosed vulnerabilities for initial access into victim networks.

T1197
BITS Jobs
GroupLeviathan

Leviathan has used BITSAdmin to download additional tools.

T1203
Exploitation for Client Execution
GroupLeviathan

Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882.

T1204.001
Malicious Link
GroupLeviathan

Leviathan has sent spearphishing email links attempting to get a user to click.

T1204.002
Malicious File
GroupLeviathan

Leviathan has sent spearphishing attachments attempting to get a user to click.

T1218.010
Regsvr32
GroupLeviathan

Leviathan has used regsvr32 for execution.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1534
Internal Spearphishing
GroupLeviathan

Leviathan has conducted internal spearphishing within the victim's environment for lateral movement.

T1546.003
Windows Management Instrumentation Event Subscription
GroupLeviathan

Leviathan has used WMI for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1547.009
Shortcut Modification
GroupLeviathan

Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor.

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

T1559.002
Dynamic Data Exchange
GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

T1560
Archive Collected Data
GroupLeviathan

Leviathan has archived victim's data prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupLeviathan

Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files.

T1566.002
Spearphishing Link
GroupLeviathan

Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

T1572
Protocol Tunneling
GroupLeviathan

Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure.

T1583.001
Domains
GroupLeviathan

Leviathan has established domains that impersonate legitimate entities to use for targeting efforts.

T1584.004
Server
GroupLeviathan

Leviathan has used compromised legitimate websites as command and control nodes for operations.

T1584.008
Network Devices
GroupLeviathan

Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure.

T1585.001
Social Media Accounts
GroupLeviathan

Leviathan has created new social media accounts for targeting efforts.

T1585.002
Email Accounts
GroupLeviathan

Leviathan has created new email accounts for targeting efforts.

T1586.001
Social Media Accounts
GroupLeviathan

Leviathan has compromised social media accounts to conduct social engineering attacks.

T1586.002
Email Accounts
GroupLeviathan

Leviathan has compromised email accounts to conduct social engineering attacks.

T1587.004
Exploits
GroupLeviathan

Leviathan has rapidly transformed and adapted public exploit proof-of-concept code for new vulnerabilities and utilized them against target networks.

T1589.001
Credentials
GroupLeviathan

Leviathan has collected compromised credentials to use for targeting efforts.

T1595.002
Vulnerability Scanning
GroupLeviathan

Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.