ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0094×

130 examples

TechniqueUsed byProcedure example
T1583.004
Server
GroupKimsuky

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.

T1583.006
Web Services
GroupKimsuky

Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information.

T1584.001
Domains
GroupKimsuky

Kimsuky has compromised legitimate sites and used them to distribute malware.

T1585
Establish Accounts
GroupKimsuky

Kimsuky has leveraged stolen PII to create accounts.

T1585.001
Social Media Accounts
GroupKimsuky

Kimsuky has created social media accounts to monitor news and security trends as well as potential targets.

T1585.002
Email Accounts
GroupKimsuky

Kimsuky has created email accounts for phishing operations.

T1586.002
Email Accounts
GroupKimsuky

Kimsuky has compromised email accounts to send spearphishing e-mails.

T1587
Develop Capabilities
GroupKimsuky

Kimsuky created and used a mailing toolkit to use in spearphishing attacks.

T1587.001
Malware
GroupKimsuky

Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.

T1588.002
Tool
GroupKimsuky

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.

T1588.003
Code Signing Certificates
GroupKimsuky

Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper.

T1588.005
Exploits
GroupKimsuky

Kimsuky has obtained exploit code for various CVEs.

T1589.002
Email Addresses
GroupKimsuky

Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering.

T1589.003
Employee Names
GroupKimsuky

Kimsuky has collected victim employee name information.

T1591
Gather Victim Org Information
GroupKimsuky

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.

T1593.001
Social Media
GroupKimsuky

Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails.

T1593.002
Search Engines
GroupKimsuky

Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims.

T1594
Search Victim-Owned Websites
GroupKimsuky

Kimsuky has searched for information on the target company's website.

T1596
Search Open Technical Databases
GroupKimsuky

Kimsuky has used LLMs to better understand publicly reported vulnerabilities.

T1598
Phishing for Information
GroupKimsuky

Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets.

T1598.003
Spearphishing Link
GroupKimsuky

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.

T1608.001
Upload Malware
GroupKimsuky

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox.

T1620
Reflective Code Loading
GroupKimsuky

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.

T1657
Financial Theft
GroupKimsuky

Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure.

T1678
Delay Execution
GroupKimsuky

Kimsuky has utilized the Sleep function to ensure execution of scripts.

T1680
Local Storage Discovery
GroupKimsuky

Kimsuky has enumerated drives.

T1682
Query Public AI Services
GroupKimsuky

Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns.

T1684.001
Impersonation
GroupKimsuky

Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee. Kimsuky has also purported to be a Japanese diplomat to communicate with the victims.

T1685
Disable or Modify Tools
GroupKimsuky

Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user.

T1686
Disable or Modify System Firewall
GroupKimsuky

Kimsuky has been observed disabling the system firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.