ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0094×

130 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKimsuky

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1007
System Service Discovery
GroupKimsuky

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.

T1012
Query Registry
GroupKimsuky

Kimsuky has obtained specific Registry keys and values on a compromised host.

T1016
System Network Configuration Discovery
GroupKimsuky

Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`.

T1020
Automated Exfiltration
GroupKimsuky

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.

T1021.001
Remote Desktop Protocol
GroupKimsuky

Kimsuky has used RDP for direct remote point-and-click access.

T1027
Obfuscated Files or Information
GroupKimsuky

Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis.

T1027.001
Binary Padding
GroupKimsuky

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.

T1027.002
Software Packing
GroupKimsuky

Kimsuky has packed malware with UPX.

T1027.007
Dynamic API Resolution
GroupKimsuky

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

T1027.010
Command Obfuscation
GroupKimsuky

Kimsuky has encoded malicious PowerShell scripts using Base64.

T1027.012
LNK Icon Smuggling
GroupKimsuky

Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.

T1027.013
Encrypted/Encoded File
GroupKimsuky

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1027.015
Compression
GroupKimsuky

Kimsuky has delivered malicious payloads within Zip archives.

T1027.016
Junk Code Insertion
GroupKimsuky

Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection.

T1033
System Owner/User Discovery
GroupKimsuky

Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method.

T1036.004
Masquerade Task or Service
GroupKimsuky

Kimsuky has disguised services to appear as benign software or related to operating system functions.

T1036.005
Match Legitimate Resource Name or Location
GroupKimsuky

Kimsuky has renamed malware to legitimate names such as ESTCommon.dll or patch.dll. Kimsuky has also disguised payloads using legitimate file names including a PowerShell payload named chrome.ps1. Kimsuky has also used a malicious QR code that masqueraded as a legitimate package delivery service.

T1036.007
Double File Extension
GroupKimsuky

Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk.

T1040
Network Sniffing
GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

T1041
Exfiltration Over C2 Channel
GroupKimsuky

Kimsuky has exfiltrated data over its C2 channel.

T1053.005
Scheduled Task
GroupKimsuky

Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate".

T1055
Process Injection
GroupKimsuky

Kimsuky has used Win7Elevate to inject malicious code into explorer.exe.

T1055.001
Dynamic-link Library Injection
GroupKimsuky

Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`.

T1055.012
Process Hollowing
GroupKimsuky

Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1056.003
Web Portal Capture
GroupKimsuky

Kimsuky has collected credentials from a fake Google account login page.

T1057
Process Discovery
GroupKimsuky

Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.003
Windows Command Shell
GroupKimsuky

Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1059.006
Python
GroupKimsuky

Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data.

T1059.007
JavaScript
GroupKimsuky

Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1070.006
Timestomp
GroupKimsuky

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.

T1071.001
Web Protocols
GroupKimsuky

Kimsuky has used HTTP GET and POST requests for C2.

T1071.002
File Transfer Protocols
GroupKimsuky

Kimsuky has used FTP to download additional malware to the target machine.

T1071.003
Mail Protocols
GroupKimsuky

Kimsuky has used e-mail to send exfiltrated data to C2 servers.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1078.003
Local Accounts
GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

T1082
System Information Discovery
GroupKimsuky

Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`.

T1083
File and Directory Discovery
GroupKimsuky

Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways.

T1098.007
Additional Local or Domain Groups
GroupKimsuky

Kimsuky has added accounts to specific groups with net localgroup.

T1102.001
Dead Drop Resolver
GroupKimsuky

Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.002
Bidirectional Communication
GroupKimsuky

Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information.

T1105
Ingress Tool Transfer
GroupKimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.

T1106
Native API
GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

T1111
Multi-Factor Authentication Interception
GroupKimsuky

Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.