ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0096×

82 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT41

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

T1003.002
Security Account Manager
GroupAPT41

APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the reg save command or by exploiting volume shadow copies.

T1003.003
NTDS
GroupAPT41

APT41 used ntdsutil to obtain a copy of the victim environment ntds.dit file.

T1005
Data from Local System
GroupAPT41

APT41 has uploaded files and data from a compromised host.

T1008
Fallback Channels
GroupAPT41

APT41 used the Steam community page as a fallback mechanism for C2.

T1012
Query Registry
GroupAPT41

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

T1014
Rootkit
GroupAPT41

APT41 deployed rootkits on Linux systems.

T1016
System Network Configuration Discovery
GroupAPT41

APT41 collected MAC addresses from victim machines.

T1018
Remote System Discovery
GroupAPT41

APT41 has used MiPing to discover active systems in the victim network.

T1021.001
Remote Desktop Protocol
GroupAPT41

APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet.

T1021.002
SMB/Windows Admin Shares
GroupAPT41

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

T1027
Obfuscated Files or Information
GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

T1027.002
Software Packing
GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

T1030
Data Transfer Size Limits
GroupAPT41

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

T1033
System Owner/User Discovery
GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

T1036.004
Masquerade Task or Service
GroupAPT41

APT41 has created services to appear as benign system tools.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT41

APT41 attempted to masquerade their files as popular anti-virus software.

T1037
Boot or Logon Initialization Scripts
GroupAPT41

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.

T1046
Network Service Discovery
GroupAPT41

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1049
System Network Connections Discovery
GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

T1053.005
Scheduled Task
GroupAPT41

APT41 used a compromised account to create a scheduled task on a system.

T1055
Process Injection
GroupAPT41

APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.

T1056.001
Keylogging
GroupAPT41

APT41 used a keylogger called GEARSHIFT on a target system.

T1059.001
PowerShell
GroupAPT41

APT41 leveraged PowerShell to deploy malware families in victims’ environments.

T1059.003
Windows Command Shell
GroupAPT41

APT41 used cmd.exe /c to execute commands on remote machines.
APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.

T1059.004
Unix Shell
GroupAPT41

APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871.

T1069
Permission Groups Discovery
GroupAPT41

APT41 used net group commands to enumerate various Windows user groups and permissions.

T1070.003
Clear Command History
GroupAPT41

APT41 attempted to remove evidence of some of its activity by deleting Bash histories.

T1070.004
File Deletion
GroupAPT41

APT41 deleted files from the system.

T1071.001
Web Protocols
GroupAPT41

APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits.

T1071.002
File Transfer Protocols
GroupAPT41

APT41 used exploit payloads that initiate download via ftp.

T1071.004
DNS
GroupAPT41

APT41 used DNS for C2 communications.

T1078
Valid Accounts
GroupAPT41

APT41 used compromised credentials to log on to other systems.

T1082
System Information Discovery
GroupAPT41

APT41 uses multiple built-in commands such as systeminfo and `net config Workstation` to enumerate victim system basic configuration information.

T1083
File and Directory Discovery
GroupAPT41

APT41 has executed file /bin/pwd on exploited victims, perhaps to return architecture related information.

T1087.001
Local Account
GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

T1087.002
Domain Account
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

T1090
Proxy
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

T1098.007
Additional Local or Domain Groups
GroupAPT41

APT41 has added user accounts to the User and Admin groups.

T1102.001
Dead Drop Resolver
GroupAPT41

APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet.

T1104
Multi-Stage Channels
GroupAPT41

APT41 used the storescyncsvc.dll BEACON backdoor to download a secondary backdoor.

T1105
Ingress Tool Transfer
GroupAPT41

APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities.

T1110
Brute Force
GroupAPT41

APT41 performed password brute-force attacks on the local admin account.

T1112
Modify Registry
GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

T1133
External Remote Services
GroupAPT41

APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service.

T1135
Network Share Discovery
GroupAPT41

APT41 used the net share command as part of network reconnaissance.

T1136.001
Local Account
GroupAPT41

APT41 has created user accounts.

T1190
Exploit Public-Facing Application
GroupAPT41

APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network.

T1195.002
Compromise Software Supply Chain
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.