Real-world descriptions of how a group, tool or campaign used a technique.
130 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1113 Screen Capture |
GroupKimsuky | Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware. |
| T1114.002 Remote Email Collection |
GroupKimsuky | Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP. |
| T1114.003 Email Forwarding Rule |
GroupKimsuky | Kimsuky has set auto-forward rules on victim's e-mail accounts. |
| T1115 Clipboard Data |
GroupKimsuky | Kimsuky has the ability to steal data from the clipboard. |
| T1124 System Time Discovery |
GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| T1132.002 Non-Standard Encoding |
GroupKimsuky | Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding. |
| T1133 External Remote Services |
GroupKimsuky | Kimsuky has used RDP to establish persistence. |
| T1136.001 Local Account |
GroupKimsuky | Kimsuky has created accounts with |
| T1140 Deobfuscate/Decode Files or Information |
GroupKimsuky | Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure. |
| T1176.001 Browser Extensions |
GroupKimsuky | Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies. |
| T1185 Browser Session Hijacking |
GroupKimsuky | Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms. |
| T1190 Exploit Public-Facing Application |
GroupKimsuky | Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688. |
| T1204.001 Malicious Link |
GroupKimsuky | Kimsuky has lured victims into clicking malicious links. |
| T1204.002 Malicious File |
GroupKimsuky | Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background. |
| T1204.004 Malicious Copy and Paste |
GroupKimsuky | Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code. |
| T1205 Traffic Signaling |
GroupKimsuky | Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters. |
| T1217 Browser Information Discovery |
GroupKimsuky | Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.010 Regsvr32 |
GroupKimsuky | Kimsuky has executed malware with |
| T1218.011 Rundll32 |
GroupKimsuky | Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network. |
| T1219.002 Remote Desktop Software |
GroupKimsuky | Kimsuky has used a modified TeamViewer client as a command and control channel. |
| T1480.002 Mutual Exclusion |
GroupKimsuky | Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication. |
| T1489 Service Stop |
GroupKimsuky | Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox. |
| T1497.001 System Checks |
GroupKimsuky | Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`. |
| T1505.003 Web Shell |
GroupKimsuky | Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code. |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1534 Internal Spearphishing |
GroupKimsuky | Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information. |
| T1539 Steal Web Session Cookie |
GroupKimsuky | Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies. |
| T1543.003 Windows Service |
GroupKimsuky | Kimsuky has created new services for persistence. |
| T1546.001 Change Default File Association |
GroupKimsuky | Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1550.002 Pass the Hash |
GroupKimsuky | Kimsuky has used pass the hash for authentication to remote access software used in C2. |
| T1552.001 Credentials In Files |
GroupKimsuky | Kimsuky has used tools that are capable of obtaining credentials from saved mail. |
| T1552.004 Private Keys |
GroupKimsuky | Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`. |
| T1553.002 Code Signing |
GroupKimsuky | Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1557 Adversary-in-the-Middle |
GroupKimsuky | Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website. |
| T1559.001 Component Object Model |
GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| T1560.001 Archive via Utility |
GroupKimsuky | Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration. |
| T1560.003 Archive via Custom Method |
GroupKimsuky | Kimsuky has used RC4 encryption before exfil. |
| T1564.002 Hidden Users |
GroupKimsuky | Kimsuky has run |
| T1564.003 Hidden Window |
GroupKimsuky | Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows. |
| T1564.011 Ignore Process Interrupts |
GroupKimsuky | Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events. |
| T1566 Phishing |
GroupKimsuky | Kimsuky has used spearphishing to gain initial access and intelligence. |
| T1566.001 Spearphishing Attachment |
GroupKimsuky | Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links. |
| T1566.002 Spearphishing Link |
GroupKimsuky | Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain. |
| T1567.002 Exfiltration to Cloud Storage |
GroupKimsuky | Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information. |
| T1568 Dynamic Resolution |
GroupKimsuky | Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea. |
| T1583 Acquire Infrastructure |
GroupKimsuky | Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure. |
| T1583.001 Domains |
GroupKimsuky | Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.