ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0094×

130 examples

TechniqueUsed byProcedure example
T1113
Screen Capture
GroupKimsuky

Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware.

T1114.002
Remote Email Collection
GroupKimsuky

Kimsuky has used tools such as the MailFetch mail crawler to collect victim emails (excluding spam) from online services via IMAP.

T1114.003
Email Forwarding Rule
GroupKimsuky

Kimsuky has set auto-forward rules on victim's e-mail accounts.

T1115
Clipboard Data
GroupKimsuky

Kimsuky has the ability to steal data from the clipboard.

T1124
System Time Discovery
GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

T1132.002
Non-Standard Encoding
GroupKimsuky

Kimsuky has obfuscated HTTP Post request communications utilizing XOR with a designated key, followed by Base64 encoding.

T1133
External Remote Services
GroupKimsuky

Kimsuky has used RDP to establish persistence.

T1136.001
Local Account
GroupKimsuky

Kimsuky has created accounts with net user.

T1140
Deobfuscate/Decode Files or Information
GroupKimsuky

Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure.

T1176.001
Browser Extensions
GroupKimsuky

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.

T1185
Browser Session Hijacking
GroupKimsuky

Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms.

T1190
Exploit Public-Facing Application
GroupKimsuky

Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688.

T1204.001
Malicious Link
GroupKimsuky

Kimsuky has lured victims into clicking malicious links.

T1204.002
Malicious File
GroupKimsuky

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions. Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.

T1204.004
Malicious Copy and Paste
GroupKimsuky

Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.

T1205
Traffic Signaling
GroupKimsuky

Kimsuky has used TRANSLATEXT to redirect clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1217
Browser Information Discovery
GroupKimsuky

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.010
Regsvr32
GroupKimsuky

Kimsuky has executed malware with regsvr32s.

T1218.011
Rundll32
GroupKimsuky

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.

T1219.002
Remote Desktop Software
GroupKimsuky

Kimsuky has used a modified TeamViewer client as a command and control channel.

T1480.002
Mutual Exclusion
GroupKimsuky

Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication.

T1489
Service Stop
GroupKimsuky

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.

T1497.001
System Checks
GroupKimsuky

Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`.

T1505.003
Web Shell
GroupKimsuky

Kimsuky has used modified versions of open source PHP web shells to maintain access, often adding "Dinosaur" references within the code.

T1518.001
Security Software Discovery
GroupKimsuky

Kimsuky has checked for the presence of antivirus software with powershell Get-CimInstance -Namespace root/securityCenter2 – classname antivirusproduct. Kimsuky has also obtained details on antivirus software through WMI queries using `Win32_OperatingSystem` and `SecurityCenter2.AntiVirusProduct`. Kimsuky has also checked the status of Windows Defender through the use `cmd /s sc query WinDefend`.

T1534
Internal Spearphishing
GroupKimsuky

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.

T1539
Steal Web Session Cookie
GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

T1543.003
Windows Service
GroupKimsuky

Kimsuky has created new services for persistence.

T1546.001
Change Default File Association
GroupKimsuky

Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1550.002
Pass the Hash
GroupKimsuky

Kimsuky has used pass the hash for authentication to remote access software used in C2.

T1552.001
Credentials In Files
GroupKimsuky

Kimsuky has used tools that are capable of obtaining credentials from saved mail.

T1552.004
Private Keys
GroupKimsuky

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.

T1553.002
Code Signing
GroupKimsuky

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1557
Adversary-in-the-Middle
GroupKimsuky

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.

T1559.001
Component Object Model
GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

T1560.001
Archive via Utility
GroupKimsuky

Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration.

T1560.003
Archive via Custom Method
GroupKimsuky

Kimsuky has used RC4 encryption before exfil.

T1564.002
Hidden Users
GroupKimsuky

Kimsuky has run reg add ‘HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList’ /v to hide a newly created user.

T1564.003
Hidden Window
GroupKimsuky

Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows.

T1564.011
Ignore Process Interrupts
GroupKimsuky

Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events.

T1566
Phishing
GroupKimsuky

Kimsuky has used spearphishing to gain initial access and intelligence.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1566.002
Spearphishing Link
GroupKimsuky

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.

T1567.002
Exfiltration to Cloud Storage
GroupKimsuky

Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information.

T1568
Dynamic Resolution
GroupKimsuky

Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea.

T1583
Acquire Infrastructure
GroupKimsuky

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.

T1583.001
Domains
GroupKimsuky

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.