Real-world descriptions of how a group, tool or campaign used a technique.
82 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1003.002 Security Account Manager |
GroupAPT41 | APT41 extracted user account data from the Security Account Managerr (SAM), making a copy of this database from the registry using the |
| T1003.003 NTDS |
GroupAPT41 | APT41 used ntdsutil to obtain a copy of the victim environment |
| T1005 Data from Local System |
GroupAPT41 | APT41 has uploaded files and data from a compromised host. |
| T1008 Fallback Channels |
GroupAPT41 | APT41 used the Steam community page as a fallback mechanism for C2. |
| T1012 Query Registry |
GroupAPT41 | APT41 queried registry values to determine items such as configured RDP ports and network configurations. |
| T1014 Rootkit |
GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1018 Remote System Discovery |
GroupAPT41 | APT41 has used MiPing to discover active systems in the victim network. |
| T1021.001 Remote Desktop Protocol |
GroupAPT41 | APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT41 | APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| T1027 Obfuscated Files or Information |
GroupAPT41 | APT41 used VMProtected binaries in multiple intrusions. |
| T1027.002 Software Packing |
GroupAPT41 | APT41 uses packers such as Themida to obfuscate malicious files. |
| T1030 Data Transfer Size Limits |
GroupAPT41 | APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection. |
| T1033 System Owner/User Discovery |
GroupAPT41 | APT41 has executed |
| T1036.004 Masquerade Task or Service |
GroupAPT41 | APT41 has created services to appear as benign system tools. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT41 | APT41 attempted to masquerade their files as popular anti-virus software. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT41 | APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit. |
| T1046 Network Service Discovery |
GroupAPT41 | APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets. |
| T1047 Windows Management Instrumentation |
GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1053.005 Scheduled Task |
GroupAPT41 | APT41 used a compromised account to create a scheduled task on a system. |
| T1055 Process Injection |
GroupAPT41 | APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. |
| T1056.001 Keylogging |
GroupAPT41 | APT41 used a keylogger called GEARSHIFT on a target system. |
| T1059.001 PowerShell |
GroupAPT41 | APT41 leveraged PowerShell to deploy malware families in victims’ environments. |
| T1059.003 Windows Command Shell |
GroupAPT41 | APT41 used |
| T1059.004 Unix Shell |
GroupAPT41 | APT41 used Linux shell commands for system survey and information gathering prior to exploitation of vulnerabilities such as CVE-2019-19871. |
| T1069 Permission Groups Discovery |
GroupAPT41 | APT41 used |
| T1070.003 Clear Command History |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by deleting Bash histories. |
| T1070.004 File Deletion |
GroupAPT41 | APT41 deleted files from the system. |
| T1071.001 Web Protocols |
GroupAPT41 | APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits. |
| T1071.002 File Transfer Protocols |
GroupAPT41 | |
| T1071.004 DNS |
GroupAPT41 | APT41 used DNS for C2 communications. |
| T1078 Valid Accounts |
GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| T1082 System Information Discovery |
GroupAPT41 | APT41 uses multiple built-in commands such as |
| T1083 File and Directory Discovery |
GroupAPT41 | APT41 has executed |
| T1087.001 Local Account |
GroupAPT41 | APT41 used built-in |
| T1087.002 Domain Account |
GroupAPT41 | APT41 used built-in |
| T1090 Proxy |
GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT41 | APT41 has added user accounts to the User and Admin groups. |
| T1102.001 Dead Drop Resolver |
GroupAPT41 | APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet. |
| T1104 Multi-Stage Channels |
GroupAPT41 | APT41 used the storescyncsvc.dll BEACON backdoor to download a secondary backdoor. |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1110 Brute Force |
GroupAPT41 | APT41 performed password brute-force attacks on the local admin account. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1133 External Remote Services |
GroupAPT41 | APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service. |
| T1135 Network Share Discovery |
GroupAPT41 | APT41 used the |
| T1136.001 Local Account |
GroupAPT41 | APT41 has created user accounts. |
| T1190 Exploit Public-Facing Application |
GroupAPT41 | APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network. |
| T1195.002 Compromise Software Supply Chain |
GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.