Real-world descriptions of how a group, tool or campaign used a technique.
130 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.004 Server |
GroupKimsuky | Kimsuky has purchased hosting servers with virtual currency and prepaid cards. |
| T1583.006 Web Services |
GroupKimsuky | Kimsuky has hosted content used for targeting efforts via web services such as Blogspot. Kimsuky has also leveraged Dropbox for hosting payloads and uploading victim system information. |
| T1584.001 Domains |
GroupKimsuky | Kimsuky has compromised legitimate sites and used them to distribute malware. |
| T1585 Establish Accounts |
GroupKimsuky | Kimsuky has leveraged stolen PII to create accounts. |
| T1585.001 Social Media Accounts |
GroupKimsuky | Kimsuky has created social media accounts to monitor news and security trends as well as potential targets. |
| T1585.002 Email Accounts |
GroupKimsuky | Kimsuky has created email accounts for phishing operations. |
| T1586.002 Email Accounts |
GroupKimsuky | Kimsuky has compromised email accounts to send spearphishing e-mails. |
| T1587 Develop Capabilities |
GroupKimsuky | Kimsuky created and used a mailing toolkit to use in spearphishing attacks. |
| T1587.001 Malware |
GroupKimsuky | Kimsuky has developed its own unique malware such as MailFetch.py for use in operations. |
| T1588.002 Tool |
GroupKimsuky | Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec. |
| T1588.003 Code Signing Certificates |
GroupKimsuky | Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1588.005 Exploits |
GroupKimsuky | Kimsuky has obtained exploit code for various CVEs. |
| T1589.002 Email Addresses |
GroupKimsuky | Kimsuky has collected valid email addresses including personal accounts that were subsequently used for spearphishing and other forms of social engineering. |
| T1589.003 Employee Names |
GroupKimsuky | Kimsuky has collected victim employee name information. |
| T1591 Gather Victim Org Information |
GroupKimsuky | Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others. Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest. |
| T1593.001 Social Media |
GroupKimsuky | Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails. |
| T1593.002 Search Engines |
GroupKimsuky | Kimsuky has searched for vulnerabilities, tools, and geopolitical trends on Google to target victims. |
| T1594 Search Victim-Owned Websites |
GroupKimsuky | Kimsuky has searched for information on the target company's website. |
| T1596 Search Open Technical Databases |
GroupKimsuky | Kimsuky has used LLMs to better understand publicly reported vulnerabilities. |
| T1598 Phishing for Information |
GroupKimsuky | Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets. |
| T1598.003 Spearphishing Link |
GroupKimsuky | Kimsuky has used links in e-mail to steal account information including web beacons for target profiling. Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL. |
| T1608.001 Upload Malware |
GroupKimsuky | Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants. Kimsuky has also hosted malicious payloads on Dropbox. |
| T1620 Reflective Code Loading |
GroupKimsuky | Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`. |
| T1657 Financial Theft |
GroupKimsuky | Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure. |
| T1678 Delay Execution |
GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
| T1682 Query Public AI Services |
GroupKimsuky | Kimsuky has used LLMs to identify think tanks, government organizations, and experts to inform targeting for spearphishing campaigns. |
| T1684.001 Impersonation |
GroupKimsuky | Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee. Kimsuky has also purported to be a Japanese diplomat to communicate with the victims. |
| T1685 Disable or Modify Tools |
GroupKimsuky | Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user. |
| T1686 Disable or Modify System Firewall |
GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.