ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0078×

16 examples

TechniqueUsed byProcedure example
T1055.002
Portable Executable Injection
GroupGorgon Group

Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.

T1055.012
Process Hollowing
GroupGorgon Group

Gorgon Group malware can use process hollowing to inject one of its trojans into another process.

T1059.001
PowerShell
GroupGorgon Group

Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine.

T1059.003
Windows Command Shell
GroupGorgon Group

Gorgon Group malware can use cmd.exe to download and execute payloads and to execute commands on the system.

T1059.005
Visual Basic
GroupGorgon Group

Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines.

T1105
Ingress Tool Transfer
GroupGorgon Group

Gorgon Group malware can download additional files from C2 servers.

T1106
Native API
GroupGorgon Group

Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution.

T1112
Modify Registry
GroupGorgon Group

Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under HKCU\Software\Microsoft\Office\.

T1140
Deobfuscate/Decode Files or Information
GroupGorgon Group

Gorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file.

T1204.002
Malicious File
GroupGorgon Group

Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder
GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1547.009
Shortcut Modification
GroupGorgon Group

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1564.003
Hidden Window
GroupGorgon Group

Gorgon Group has used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1566.001
Spearphishing Attachment
GroupGorgon Group

Gorgon Group sent emails to victims with malicious Microsoft Office documents attached.

T1588.002
Tool
GroupGorgon Group

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

T1685
Disable or Modify Tools
GroupGorgon Group

Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the taskkill command.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.