Real-world descriptions of how a group, tool or campaign used a technique.
50 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
| T1003.001 LSASS Memory |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE. |
| T1021.001 Remote Desktop Protocol |
GroupLeviathan | Leviathan has targeted RDP credentials and used it to move through the victim environment. |
| T1021.004 SSH |
GroupLeviathan | Leviathan used ssh for internal reconnaissance. |
| T1027.001 Binary Padding |
GroupLeviathan | Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection. |
| T1027.003 Steganography |
GroupLeviathan | Leviathan has used steganography to hide stolen data inside other files stored on Github. |
| T1027.013 Encrypted/Encoded File |
GroupLeviathan | Leviathan has obfuscated code using base64. |
| T1027.015 Compression |
GroupLeviathan | Leviathan has obfuscated code using gzip compression. |
| T1041 Exfiltration Over C2 Channel |
GroupLeviathan | Leviathan has exfiltrated data over its C2 channel. |
| T1047 Windows Management Instrumentation |
GroupLeviathan | Leviathan has used WMI for execution. |
| T1055.001 Dynamic-link Library Injection |
GroupLeviathan | Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1059.005 Visual Basic |
GroupLeviathan | Leviathan has used VBScript. |
| T1074.001 Local Data Staging |
GroupLeviathan | Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories. |
| T1074.002 Remote Data Staging |
GroupLeviathan | Leviathan has staged data remotely prior to exfiltration. |
| T1078 Valid Accounts |
GroupLeviathan | Leviathan has obtained valid accounts to gain initial access. |
| T1090.003 Multi-hop Proxy |
GroupLeviathan | Leviathan has used multi-hop proxies to disguise the source of their malicious traffic. |
| T1102.003 One-Way Communication |
GroupLeviathan | Leviathan has received C2 instructions from user profiles created on legitimate websites such as Github and TechNet. |
| T1105 Ingress Tool Transfer |
GroupLeviathan | Leviathan has downloaded additional scripts and files from adversary-controlled servers. |
| T1133 External Remote Services |
GroupLeviathan | Leviathan has used external remote services such as virtual private networks (VPN) to gain initial access. |
| T1140 Deobfuscate/Decode Files or Information |
GroupLeviathan | Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors. |
| T1189 Drive-by Compromise |
GroupLeviathan | Leviathan has infected victims using watering holes. |
| T1190 Exploit Public-Facing Application |
GroupLeviathan | Leviathan has used exploits against publicly-disclosed vulnerabilities for initial access into victim networks. |
| T1197 BITS Jobs |
GroupLeviathan | |
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1204.001 Malicious Link |
GroupLeviathan | Leviathan has sent spearphishing email links attempting to get a user to click. |
| T1204.002 Malicious File |
GroupLeviathan | Leviathan has sent spearphishing attachments attempting to get a user to click. |
| T1218.010 Regsvr32 |
GroupLeviathan | Leviathan has used regsvr32 for execution. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1534 Internal Spearphishing |
GroupLeviathan | Leviathan has conducted internal spearphishing within the victim's environment for lateral movement. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupLeviathan | Leviathan has used WMI for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1547.009 Shortcut Modification |
GroupLeviathan | Leviathan has used JavaScript to create a shortcut file in the Startup folder that points to its main backdoor. |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
| T1559.002 Dynamic Data Exchange |
GroupLeviathan | Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents. |
| T1560 Archive Collected Data |
GroupLeviathan | Leviathan has archived victim's data prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupLeviathan | Leviathan has sent spearphishing emails with malicious attachments, including .rtf, .doc, and .xls files. |
| T1566.002 Spearphishing Link |
GroupLeviathan | Leviathan has sent spearphishing emails with links, often using a fraudulent lookalike domain and stolen branding. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
| T1572 Protocol Tunneling |
GroupLeviathan | Leviathan has used protocol tunneling to further conceal C2 communications and infrastructure. |
| T1583.001 Domains |
GroupLeviathan | Leviathan has established domains that impersonate legitimate entities to use for targeting efforts. |
| T1584.004 Server |
GroupLeviathan | Leviathan has used compromised legitimate websites as command and control nodes for operations. |
| T1584.008 Network Devices |
GroupLeviathan | Leviathan has used compromised networking devices, such as small office/home office (SOHO) devices, as operational command and control infrastructure. |
| T1585.001 Social Media Accounts |
GroupLeviathan | Leviathan has created new social media accounts for targeting efforts. |
| T1585.002 Email Accounts |
GroupLeviathan | Leviathan has created new email accounts for targeting efforts. |
| T1586.001 Social Media Accounts |
GroupLeviathan | Leviathan has compromised social media accounts to conduct social engineering attacks. |
| T1586.002 Email Accounts |
GroupLeviathan | Leviathan has compromised email accounts to conduct social engineering attacks. |
| T1587.004 Exploits |
GroupLeviathan | Leviathan has rapidly transformed and adapted public exploit proof-of-concept code for new vulnerabilities and utilized them against target networks. |
| T1589.001 Credentials |
GroupLeviathan | Leviathan has collected compromised credentials to use for targeting efforts. |
| T1595.002 Vulnerability Scanning |
GroupLeviathan | Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.