Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1027.010 Command Obfuscation |
GroupAPT19 | APT19 used Base64 to obfuscate executed commands. |
| T1027.013 Encrypted/Encoded File |
GroupAPT19 | APT19 used Base64 to obfuscate payloads. |
| T1033 System Owner/User Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
| T1059 Command and Scripting Interpreter |
GroupAPT19 | APT19 downloaded and launched code within a SCT file. |
| T1059.001 PowerShell |
GroupAPT19 | APT19 used PowerShell commands to execute payloads. |
| T1071.001 Web Protocols |
GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1082 System Information Discovery |
GroupAPT19 | APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| T1112 Modify Registry |
GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
| T1132.001 Standard Encoding |
GroupAPT19 | An APT19 HTTP malware variant used Base64 to encode communications to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT19 | An APT19 HTTP malware variant decrypts strings using single-byte XOR keys. |
| T1189 Drive-by Compromise |
GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| T1204.002 Malicious File |
GroupAPT19 | APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails. |
| T1218.010 Regsvr32 |
GroupAPT19 | APT19 used Regsvr32 to bypass application control techniques. |
| T1218.011 Rundll32 |
GroupAPT19 | APT19 configured its payload to inject into the rundll32.exe. |
| T1543.003 Windows Service |
GroupAPT19 | An APT19 Port 22 malware variant registers itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT19 | An APT19 HTTP malware variant establishes persistence by setting the Registry key |
| T1564.003 Hidden Window |
GroupAPT19 | APT19 used |
| T1566.001 Spearphishing Attachment |
GroupAPT19 | APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits. |
| T1574.001 DLL |
GroupAPT19 | APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL. |
| T1588.002 Tool |
GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.