ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0080×

34 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupCobalt Group

Cobalt Group has used Remote Desktop Protocol to conduct lateral movement.

T1027.010
Command Obfuscation
GroupCobalt Group

Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4.

T1037.001
Logon Script (Windows)
GroupCobalt Group

Cobalt Group has added persistence by registering the file name for the next stage malware under HKCU\Environment\UserInitMprLogonScript.

T1046
Network Service Discovery
GroupCobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.

T1053.005
Scheduled Task
GroupCobalt Group

Cobalt Group has created Windows tasks to establish persistence.

T1055
Process Injection
GroupCobalt Group

Cobalt Group has injected code into trusted processes.

T1059.001
PowerShell
GroupCobalt Group

Cobalt Group has used powershell.exe to download and execute scripts.

T1059.003
Windows Command Shell
GroupCobalt Group

Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files.

T1059.005
Visual Basic
GroupCobalt Group

Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution.

T1059.007
JavaScript
GroupCobalt Group

Cobalt Group has executed JavaScript scriptlets on the victim's machine.

T1068
Exploitation for Privilege Escalation
GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1070.004
File Deletion
GroupCobalt Group

Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks.

T1071.001
Web Protocols
GroupCobalt Group

Cobalt Group has used HTTPS for C2.

T1071.004
DNS
GroupCobalt Group

Cobalt Group has used DNS tunneling for C2.

T1105
Ingress Tool Transfer
GroupCobalt Group

Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files.

T1195.002
Compromise Software Supply Chain
GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

T1203
Exploitation for Client Execution
GroupCobalt Group

Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759.

T1204.001
Malicious Link
GroupCobalt Group

Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine.

T1204.002
Malicious File
GroupCobalt Group

Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine.

T1218.003
CMSTP
GroupCobalt Group

Cobalt Group has used the command cmstp.exe /s /ns C:\Users\ADMINI~W\AppData\Local\Temp\XKNqbpzl.txt to bypass AppLocker and launch a malicious script.

T1218.008
Odbcconf
GroupCobalt Group

Cobalt Group has used odbcconf to proxy the execution of malicious DLL files.

T1218.010
Regsvr32
GroupCobalt Group

Cobalt Group has used regsvr32.exe to execute scripts.

T1219
Remote Access Tools
GroupCobalt Group

Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost.

T1220
XSL Script Processing
GroupCobalt Group

Cobalt Group used msxsl.exe to bypass AppLocker and to invoke Jscript code from an XSL file.

T1518.001
Security Software Discovery
GroupCobalt Group

Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine.

T1543.003
Windows Service
GroupCobalt Group

Cobalt Group has created new services to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupCobalt Group

Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike.

T1548.002
Bypass User Account Control
GroupCobalt Group

Cobalt Group has bypassed UAC.

T1559.002
Dynamic Data Exchange
GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

T1566.001
Spearphishing Attachment
GroupCobalt Group

Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables.

T1566.002
Spearphishing Link
GroupCobalt Group

Cobalt Group has sent emails with URLs pointing to malicious documents.

T1572
Protocol Tunneling
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1573.002
Asymmetric Cryptography
GroupCobalt Group

Cobalt Group has used the Plink utility to create SSH tunnels.

T1588.002
Tool
GroupCobalt Group

Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.