Real-world descriptions of how a group, tool or campaign used a technique.
53 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| T1003.001 LSASS Memory |
GroupAPT39 | APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| T1005 Data from Local System |
GroupAPT39 | APT39 has used various tools to steal files from the compromised host. |
| T1012 Query Registry |
GroupAPT39 | APT39 has used various strains of malware to query the Registry. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1021.001 Remote Desktop Protocol |
GroupAPT39 | APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT39 | APT39 has used SMB for lateral movement. |
| T1021.004 SSH |
GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1027.013 Encrypted/Encoded File |
GroupAPT39 | APT39 has used malware to drop encrypted CAB files. |
| T1033 System Owner/User Discovery |
GroupAPT39 | |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT39 | APT39 has exfiltrated stolen victim data through C2 communications. |
| T1046 Network Service Discovery |
GroupAPT39 | APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| T1053.005 Scheduled Task |
GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| T1056 Input Capture |
GroupAPT39 | APT39 has utilized tools to capture mouse movements. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1059.001 PowerShell |
GroupAPT39 | APT39 has used PowerShell to execute malicious code. |
| T1059.005 Visual Basic |
GroupAPT39 | APT39 has utilized malicious VBS scripts in malware. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1059.010 AutoHotKey & AutoIT |
GroupAPT39 | APT39 has utilized AutoIt malware scripts embedded in Microsoft Office documents or malicious links. |
| T1070.004 File Deletion |
GroupAPT39 | APT39 has used malware to delete files after they are deployed on a compromised host. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1071.004 DNS |
GroupAPT39 | APT39 has used remote access tools that leverage DNS in communications with C2. |
| T1074.001 Local Data Staging |
GroupAPT39 | APT39 has utilized tools to aggregate data prior to exfiltration. |
| T1078 Valid Accounts |
GroupAPT39 | APT39 has used stolen credentials to compromise Outlook Web Access (OWA). |
| T1083 File and Directory Discovery |
GroupAPT39 | APT39 has used tools with the ability to search for files on a compromised host. |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1090.002 External Proxy |
GroupAPT39 | APT39 has used various tools to proxy C2 communications. |
| T1102.002 Bidirectional Communication |
GroupAPT39 | APT39 has communicated with C2 through files uploaded to and downloaded from DropBox. |
| T1105 Ingress Tool Transfer |
GroupAPT39 | APT39 has downloaded tools to compromised hosts. |
| T1110 Brute Force |
GroupAPT39 | APT39 has used Ncrack to reveal credentials. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1115 Clipboard Data |
GroupAPT39 | APT39 has used tools capable of stealing contents of the clipboard. |
| T1135 Network Share Discovery |
GroupAPT39 | APT39 has used the post exploitation tool CrackMapExec to enumerate network shares. |
| T1136.001 Local Account |
GroupAPT39 | APT39 has created accounts on multiple compromised hosts to perform actions within the network. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT39 | APT39 has used malware to decrypt encrypted CAB files. |
| T1190 Exploit Public-Facing Application |
GroupAPT39 | APT39 has used SQL injection for initial compromise. |
| T1197 BITS Jobs |
GroupAPT39 | APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host. |
| T1204.001 Malicious Link |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1505.003 Web Shell |
GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| T1546.010 AppInit DLLs |
GroupAPT39 | APT39 has used malware to set |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT39 | APT39 has maintained persistence using the startup folder. |
| T1547.009 Shortcut Modification |
GroupAPT39 | APT39 has modified LNK shortcuts. |
| T1553.006 Code Signing Policy Modification |
GroupAPT39 | APT39 has used malware to turn off the |
| T1555 Credentials from Password Stores |
GroupAPT39 | APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords. |
| T1560.001 Archive via Utility |
GroupAPT39 | APT39 has used WinRAR and 7-Zip to compress an archive stolen data. |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.