Real-world descriptions of how a group, tool or campaign used a technique.
82 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1197 BITS Jobs |
GroupAPT41 | |
| T1203 Exploitation for Client Execution |
GroupAPT41 | APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396. |
| T1213.003 Code Repositories |
GroupAPT41 | APT41 cloned victim user Git repositories during intrusions. |
| T1218.001 Compiled HTML File |
GroupAPT41 | APT41 used compiled HTML (.chm) files for targeting. |
| T1218.011 Rundll32 |
GroupAPT41 | APT41 has used rundll32.exe to execute a loader. |
| T1480.001 Environmental Keying |
GroupAPT41 | APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number. |
| T1484.001 Group Policy Modification |
GroupAPT41 | APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware. |
| T1486 Data Encrypted for Impact |
GroupAPT41 | APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers. |
| T1496.001 Compute Hijacking |
GroupAPT41 | APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment. |
| T1542.003 Bootkit |
GroupAPT41 | APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems. |
| T1543.003 Windows Service |
GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| T1546.008 Accessibility Features |
GroupAPT41 | APT41 leveraged sticky keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT41 | APT41 created and modified startup files for persistence. APT41 added a registry key in |
| T1550.002 Pass the Hash |
GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| T1553.002 Code Signing |
GroupAPT41 | APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations. |
| T1555 Credentials from Password Stores |
GroupAPT41 | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases. |
| T1555.003 Credentials from Web Browsers |
GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| T1560.001 Archive via Utility |
GroupAPT41 | APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupAPT41 | APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims. |
| T1568.002 Domain Generation Algorithms |
GroupAPT41 | APT41 has used DGAs to change their C2 servers monthly. |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
| T1570 Lateral Tool Transfer |
GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| T1574.001 DLL |
GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| T1574.006 Dynamic Linker Hijacking |
GroupAPT41 | APT41 has configured payloads to load via LD_PRELOAD. |
| T1588.002 Tool |
GroupAPT41 | APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor. |
| T1595.002 Vulnerability Scanning |
GroupAPT41 | APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications. |
| T1595.003 Wordlist Scanning |
GroupAPT41 | APT41 leverages various tools and frameworks to brute-force directories on web servers. |
| T1596.005 Scan Databases |
GroupAPT41 | APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims. |
| T1599 Network Boundary Bridging |
GroupAPT41 | APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP. |
| T1684.001 Impersonation |
GroupAPT41 | APT41 impersonated an employee at a video game developer company to send phishing emails. |
| T1685 Disable or Modify Tools |
GroupAPT41 | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging. |
| T1685.005 Clear Windows Event Logs |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.