ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0091×

28 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSilence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

T1018
Remote System Discovery
GroupSilence

Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts.

T1021.001
Remote Desktop Protocol
GroupSilence

Silence has used RDP for lateral movement.

T1027.010
Command Obfuscation
GroupSilence

Silence has used environment variable string substitution for obfuscation.

T1036.005
Match Legitimate Resource Name or Location
GroupSilence

Silence has named its backdoor "WINWORD.exe".

T1053.005
Scheduled Task
GroupSilence

Silence has used scheduled tasks to stage its operation.

T1055
Process Injection
GroupSilence

Silence has injected a DLL library containing a Trojan into the fwmain32.exe process.

T1059.001
PowerShell
GroupSilence

Silence has used PowerShell to download and execute payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1059.005
Visual Basic
GroupSilence

Silence has used VBS scripts.

T1059.007
JavaScript
GroupSilence

Silence has used JS scripts.

T1070.004
File Deletion
GroupSilence

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1072
Software Deployment Tools
GroupSilence

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

T1078
Valid Accounts
GroupSilence

Silence has used compromised credentials to log on to other systems and escalate privileges.

T1090.002
External Proxy
GroupSilence

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

T1105
Ingress Tool Transfer
GroupSilence

Silence has downloaded additional modules and malware to victim’s machines.

T1106
Native API
GroupSilence

Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks.

T1112
Modify Registry
GroupSilence

Silence can create, delete, or modify a specified Registry key or value.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1125
Video Capture
GroupSilence

Silence has been observed making videos of victims to observe bank employees day to day activities.

T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1547.001
Registry Run Keys / Startup Folder
GroupSilence

Silence has used HKCU\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and the Startup folder to establish persistence.

T1553.002
Code Signing
GroupSilence

Silence has used a valid certificate to sign their primary loader Silence.Downloader (aka TrueBot).

T1566.001
Spearphishing Attachment
GroupSilence

Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1571
Non-Standard Port
GroupSilence

Silence has used port 444 when sending data about the system from the client to the server.

T1588.002
Tool
GroupSilence

Silence has obtained and modified versions of publicly-available tools like Empire and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.