ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0069×

68 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMuddyWater

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1016
System Network Configuration Discovery
GroupMuddyWater

MuddyWater has used malware to collect the victim’s IP address and domain name.

T1027.003
Steganography
GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.004
Compile After Delivery
GroupMuddyWater

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1033
System Owner/User Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s username.

T1036.005
Match Legitimate Resource Name or Location
GroupMuddyWater

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.

T1041
Exfiltration Over C2 Channel
GroupMuddyWater

MuddyWater has used C2 infrastructure to receive exfiltrated data.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1049
System Network Connections Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.

T1053.005
Scheduled Task
GroupMuddyWater

MuddyWater has used scheduled tasks to establish persistence.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupMuddyWater

MuddyWater has used a custom tool for creating reverse shells.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.006
Python
GroupMuddyWater

MuddyWater has developed tools in Python including Out1.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1074.001
Local Data Staging
GroupMuddyWater

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.

T1082
System Information Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.

T1083
File and Directory Discovery
GroupMuddyWater

MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET."

T1087.002
Domain Account
GroupMuddyWater

MuddyWater has used cmd.exe net user /domain to enumerate domain users.

T1090
Proxy
GroupMuddyWater

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1102.002
Bidirectional Communication
GroupMuddyWater

MuddyWater has used web services including OneHub to distribute remote access tools.

T1104
Multi-Stage Channels
GroupMuddyWater

MuddyWater has used one C2 to obtain enumeration scripts and monitor web logs, but a different C2 to send data back.

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1113
Screen Capture
GroupMuddyWater

MuddyWater has used malware that can capture screenshots of the victim’s machine.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1137.001
Office Template Macros
GroupMuddyWater

MuddyWater has used a Word Template, Normal.dotm, for persistence.

T1140
Deobfuscate/Decode Files or Information
GroupMuddyWater

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.

T1190
Exploit Public-Facing Application
GroupMuddyWater

MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).

T1203
Exploitation for Client Execution
GroupMuddyWater

MuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution.

T1204.001
Malicious Link
GroupMuddyWater

MuddyWater has distributed URLs in phishing e-mails that link to lure documents.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.004
Malicious Copy and Paste
GroupMuddyWater

MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code.

T1210
Exploitation of Remote Services
GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

T1218.003
CMSTP
GroupMuddyWater

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.

T1218.005
Mshta
GroupMuddyWater

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.

T1218.011
Rundll32
GroupMuddyWater

MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.

T1219.002
Remote Desktop Software
GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

T1518
Software Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.

T1518.001
Security Software Discovery
GroupMuddyWater

MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.

T1534
Internal Spearphishing
GroupMuddyWater

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1548.002
Bypass User Account Control
GroupMuddyWater

MuddyWater uses various techniques to bypass UAC.

T1552.001
Credentials In Files
GroupMuddyWater

MuddyWater has run a tool that steals passwords saved in victim email.

T1555
Credentials from Password Stores
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.