ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0081×

40 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupTropic Trooper

Tropic Trooper has used scripts to collect the host's network topology.

T1020
Automated Exfiltration
GroupTropic Trooper

Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage.

T1027.003
Steganography
GroupTropic Trooper

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.013
Encrypted/Encoded File
GroupTropic Trooper

Tropic Trooper has encrypted configuration files.

T1033
System Owner/User Discovery
GroupTropic Trooper

Tropic Trooper used letmein to scan for saved usernames on the target system.

T1036.005
Match Legitimate Resource Name or Location
GroupTropic Trooper

Tropic Trooper has hidden payloads in Flash directories and fake installer files.

T1046
Network Service Discovery
GroupTropic Trooper

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.

T1049
System Network Connections Discovery
GroupTropic Trooper

Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts.

T1052.001
Exfiltration over USB
GroupTropic Trooper

Tropic Trooper has exfiltrated data using USB storage devices.

T1055.001
Dynamic-link Library Injection
GroupTropic Trooper

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1059.003
Windows Command Shell
GroupTropic Trooper

Tropic Trooper has used Windows command scripts.

T1070.004
File Deletion
GroupTropic Trooper

Tropic Trooper has deleted dropper files on an infected system using command scripts.

T1071.001
Web Protocols
GroupTropic Trooper

Tropic Trooper has used HTTP in communication with the C2.

T1071.004
DNS
GroupTropic Trooper

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

T1078.003
Local Accounts
GroupTropic Trooper

Tropic Trooper has used known administrator account credentials to execute the backdoor directly.

T1082
System Information Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s OS version.

T1083
File and Directory Discovery
GroupTropic Trooper

Tropic Trooper has monitored files' modified time.

T1091
Replication Through Removable Media
GroupTropic Trooper

Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine.

T1105
Ingress Tool Transfer
GroupTropic Trooper

Tropic Trooper has used a delivered trojan to download additional files.

T1106
Native API
GroupTropic Trooper

Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl.

T1119
Automated Collection
GroupTropic Trooper

Tropic Trooper has collected information automatically using the adversary's USBferry attack.

T1132.001
Standard Encoding
GroupTropic Trooper

Tropic Trooper has used base64 encoding to hide command strings delivered from the C2.

T1135
Network Share Discovery
GroupTropic Trooper

Tropic Trooper used netview to scan target systems for shared resources.

T1140
Deobfuscate/Decode Files or Information
GroupTropic Trooper

Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload.

T1203
Exploitation for Client Execution
GroupTropic Trooper

Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158.

T1204.002
Malicious File
GroupTropic Trooper

Tropic Trooper has lured victims into executing malware via malicious e-mail attachments.

T1221
Template Injection
GroupTropic Trooper

Tropic Trooper delivered malicious documents with the XLSX extension, typically used by OpenXML documents, but the file itself was actually an OLE (XLS) document.

T1505.003
Web Shell
GroupTropic Trooper

Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell.

T1518
Software Discovery
GroupTropic Trooper

Tropic Trooper's backdoor could list the infected system's installed software.

T1518.001
Security Software Discovery
GroupTropic Trooper

Tropic Trooper can search for anti-virus software running on the system.

T1543.003
Windows Service
GroupTropic Trooper

Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
GroupTropic Trooper

Tropic Trooper has created shortcuts in the Startup folder to establish persistence.

T1547.004
Winlogon Helper DLL
GroupTropic Trooper

Tropic Trooper has created the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and sets the value to establish persistence.

T1564.001
Hidden Files and Directories
GroupTropic Trooper

Tropic Trooper has created a hidden directory under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash\.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

T1573
Encrypted Channel
GroupTropic Trooper

Tropic Trooper has encrypted traffic with the C2 to prevent network detection.

T1573.002
Asymmetric Cryptography
GroupTropic Trooper

Tropic Trooper has used SSL to connect to C2 servers.

T1574.001
DLL
GroupTropic Trooper

Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools.

T1680
Local Storage Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s system volume information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.