ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0087×

53 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupAPT39

APT39 has used different versions of Mimikatz to obtain credentials.

T1003.001
LSASS Memory
GroupAPT39

APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials.

T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1012
Query Registry
GroupAPT39

APT39 has used various strains of malware to query the Registry.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1021.001
Remote Desktop Protocol
GroupAPT39

APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions.

T1021.002
SMB/Windows Admin Shares
GroupAPT39

APT39 has used SMB for lateral movement.

T1021.004
SSH
GroupAPT39

APT39 used secure shell (SSH) to move laterally among their targets.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1027.013
Encrypted/Encoded File
GroupAPT39

APT39 has used malware to drop encrypted CAB files.

T1033
System Owner/User Discovery
GroupAPT39

APT39 used Remexi to collect usernames from the system.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT39

APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe.

T1041
Exfiltration Over C2 Channel
GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

T1046
Network Service Discovery
GroupAPT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

T1053.005
Scheduled Task
GroupAPT39

APT39 has created scheduled tasks for persistence.

T1056
Input Capture
GroupAPT39

APT39 has utilized tools to capture mouse movements.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1059.001
PowerShell
GroupAPT39

APT39 has used PowerShell to execute malicious code.

T1059.005
Visual Basic
GroupAPT39

APT39 has utilized malicious VBS scripts in malware.

T1059.006
Python
GroupAPT39

APT39 has used a command line utility and a network scanner written in python.

T1059.010
AutoHotKey & AutoIT
GroupAPT39

APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links.

T1070.004
File Deletion
GroupAPT39

APT39 has used malware to delete files after they are deployed on a compromised host.

T1071.001
Web Protocols
GroupAPT39

APT39 has used HTTP in communications with C2.

T1071.004
DNS
GroupAPT39

APT39 has used remote access tools that leverage DNS in communications with C2.

T1074.001
Local Data Staging
GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

T1078
Valid Accounts
GroupAPT39

APT39 has used stolen credentials to compromise Outlook Web Access (OWA).

T1083
File and Directory Discovery
GroupAPT39

APT39 has used tools with the ability to search for files on a compromised host.

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1090.002
External Proxy
GroupAPT39

APT39 has used various tools to proxy C2 communications.

T1102.002
Bidirectional Communication
GroupAPT39

APT39 has communicated with C2 through files uploaded to and downloaded from DropBox.

T1105
Ingress Tool Transfer
GroupAPT39

APT39 has downloaded tools to compromised hosts.

T1110
Brute Force
GroupAPT39

APT39 has used Ncrack to reveal credentials.

T1113
Screen Capture
GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

T1115
Clipboard Data
GroupAPT39

APT39 has used tools capable of stealing contents of the clipboard.

T1135
Network Share Discovery
GroupAPT39

APT39 has used the post exploitation tool CrackMapExec to enumerate network shares.

T1136.001
Local Account
GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

T1140
Deobfuscate/Decode Files or Information
GroupAPT39

APT39 has used malware to decrypt encrypted CAB files.

T1190
Exploit Public-Facing Application
GroupAPT39

APT39 has used SQL injection for initial compromise.

T1197
BITS Jobs
GroupAPT39

APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host.

T1204.001
Malicious Link
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1505.003
Web Shell
GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

T1546.010
AppInit DLLs
GroupAPT39

APT39 has used malware to set LoadAppInit_DLLs in the Registry key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT39

APT39 has maintained persistence using the startup folder.

T1547.009
Shortcut Modification
GroupAPT39

APT39 has modified LNK shortcuts.

T1553.006
Code Signing Policy Modification
GroupAPT39

APT39 has used malware to turn off the RequireSigned feature which ensures only signed DLLs can be run on Windows.

T1555
Credentials from Password Stores
GroupAPT39

APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords.

T1560.001
Archive via Utility
GroupAPT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.