Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT37 | APT37 has collected data from victims' local systems. |
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1033 System Owner/User Discovery |
GroupAPT37 | APT37 identifies the victim username. |
| T1036.001 Invalid Code Signature |
GroupAPT37 | APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.” |
| T1053.005 Scheduled Task |
GroupAPT37 | APT37 has created scheduled tasks to run malicious scripts on a compromised host. |
| T1055 Process Injection |
GroupAPT37 | APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| T1057 Process Discovery |
GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1059 Command and Scripting Interpreter |
GroupAPT37 | APT37 has used Ruby scripts to execute payloads. |
| T1059.003 Windows Command Shell |
GroupAPT37 | APT37 has used the command-line interface. |
| T1059.005 Visual Basic |
GroupAPT37 | APT37 executes shellcode and a VBA script to decode Base64 strings. |
| T1059.006 Python |
GroupAPT37 | APT37 has used Python scripts to execute payloads. |
| T1071.001 Web Protocols |
GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| T1082 System Information Discovery |
GroupAPT37 | APT37 collects the computer name, the BIOS model, and execution path. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1106 Native API |
GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| T1120 Peripheral Device Discovery |
GroupAPT37 | APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices. |
| T1123 Audio Capture |
GroupAPT37 | APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input. |
| T1189 Drive-by Compromise |
GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| T1203 Exploitation for Client Execution |
GroupAPT37 | APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution. |
| T1204.002 Malicious File |
GroupAPT37 | APT37 has sent spearphishing attachments attempting to get a user to open them. |
| T1529 System Shutdown/Reboot |
GroupAPT37 | APT37 has used malware that will issue the command |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT37 | APT37's has added persistence via the Registry key |
| T1548.002 Bypass User Account Control |
GroupAPT37 | APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges. |
| T1555.003 Credentials from Web Browsers |
GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| T1559.002 Dynamic Data Exchange |
GroupAPT37 | APT37 has used Windows DDE for execution of commands and a malicious VBS. |
| T1561.002 Disk Structure Wipe |
GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.