Real-world descriptions of how a group, tool or campaign used a technique.
130 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1005 Data from Local System |
GroupKimsuky | Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1007 System Service Discovery |
GroupKimsuky | Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system. |
| T1012 Query Registry |
GroupKimsuky | Kimsuky has obtained specific Registry keys and values on a compromised host. |
| T1016 System Network Configuration Discovery |
GroupKimsuky | Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`. |
| T1020 Automated Exfiltration |
GroupKimsuky | Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames. |
| T1021.001 Remote Desktop Protocol |
GroupKimsuky | Kimsuky has used RDP for direct remote point-and-click access. |
| T1027 Obfuscated Files or Information |
GroupKimsuky | Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis. |
| T1027.001 Binary Padding |
GroupKimsuky | Kimsuky has performed padding of PowerShell command line code with over 100 spaces. |
| T1027.002 Software Packing |
GroupKimsuky | Kimsuky has packed malware with UPX. |
| T1027.007 Dynamic API Resolution |
GroupKimsuky | Kimsuky has leveraged dynamic API resolution using custom hashing techniques. |
| T1027.010 Command Obfuscation |
GroupKimsuky | Kimsuky has encoded malicious PowerShell scripts using Base64. |
| T1027.012 LNK Icon Smuggling |
GroupKimsuky | Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script. |
| T1027.013 Encrypted/Encoded File |
GroupKimsuky | Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1027.015 Compression |
GroupKimsuky | Kimsuky has delivered malicious payloads within Zip archives. |
| T1027.016 Junk Code Insertion |
GroupKimsuky | Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection. |
| T1033 System Owner/User Discovery |
GroupKimsuky | Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method. |
| T1036.004 Masquerade Task or Service |
GroupKimsuky | Kimsuky has disguised services to appear as benign software or related to operating system functions. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKimsuky | Kimsuky has renamed malware to legitimate names such as |
| T1036.007 Double File Extension |
GroupKimsuky | Kimsuky has used an additional filename extension to hide the true file type. Kimsuky has also masqueraded malicious LNK files as PDF objects using the double extension .pdf.lnk. |
| T1040 Network Sniffing |
GroupKimsuky | Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols. |
| T1041 Exfiltration Over C2 Channel |
GroupKimsuky | Kimsuky has exfiltrated data over its C2 channel. |
| T1053.005 Scheduled Task |
GroupKimsuky | Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate". |
| T1055 Process Injection |
GroupKimsuky | Kimsuky has used Win7Elevate to inject malicious code into explorer.exe. |
| T1055.001 Dynamic-link Library Injection |
GroupKimsuky | Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`. |
| T1055.012 Process Hollowing |
GroupKimsuky | Kimsuky has used a file injector DLL to spawn a benign process on the victim's system and inject the malicious payload into it via process hollowing. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1056.003 Web Portal Capture |
GroupKimsuky | Kimsuky has collected credentials from a fake Google account login page. |
| T1057 Process Discovery |
GroupKimsuky | Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.003 Windows Command Shell |
GroupKimsuky | Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1059.006 Python |
GroupKimsuky | Kimsuky has used a macOS Python implant to gather data as well as MailFetcher.py code to automatically collect email data. |
| T1059.007 JavaScript |
GroupKimsuky | Kimsuky has used JScript for logging and downloading additional tools. Kimsuky has used TRANSLATEXT, which contained four Javascript files for bypassing defenses, collecting sensitive information and screenshots, and exfiltrating data. |
| T1070.004 File Deletion |
GroupKimsuky | Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files. |
| T1070.006 Timestomp |
GroupKimsuky | Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics. |
| T1071.001 Web Protocols |
GroupKimsuky | Kimsuky has used HTTP GET and POST requests for C2. |
| T1071.002 File Transfer Protocols |
GroupKimsuky | Kimsuky has used FTP to download additional malware to the target machine. |
| T1071.003 Mail Protocols |
GroupKimsuky | Kimsuky has used e-mail to send exfiltrated data to C2 servers. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1078.003 Local Accounts |
GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| T1082 System Information Discovery |
GroupKimsuky | Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`. |
| T1083 File and Directory Discovery |
GroupKimsuky | Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways. |
| T1098.007 Additional Local or Domain Groups |
GroupKimsuky | Kimsuky has added accounts to specific groups with |
| T1102.001 Dead Drop Resolver |
GroupKimsuky | Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site. |
| T1102.002 Bidirectional Communication |
GroupKimsuky | Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information. |
| T1105 Ingress Tool Transfer |
GroupKimsuky | Kimsuky has downloaded additional scripts, tools, and malware onto victim systems. |
| T1106 Native API |
GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| T1111 Multi-Factor Authentication Interception |
GroupKimsuky | Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.