ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0096×

82 examples

TechniqueUsed byProcedure example
T1197
BITS Jobs
GroupAPT41

APT41 used BITSAdmin to download and install payloads.

T1203
Exploitation for Client Execution
GroupAPT41

APT41 leveraged the follow exploits in their operations: CVE-2012-0158, CVE-2015-1641, CVE-2017-0199, CVE-2017-11882, and CVE-2019-3396.

T1213.003
Code Repositories
GroupAPT41

APT41 cloned victim user Git repositories during intrusions.

T1218.001
Compiled HTML File
GroupAPT41

APT41 used compiled HTML (.chm) files for targeting.

T1218.011
Rundll32
GroupAPT41

APT41 has used rundll32.exe to execute a loader.

T1480.001
Environmental Keying
GroupAPT41

APT41 has encrypted payloads using the Data Protection API (DPAPI), which relies on keys tied to specific user accounts on specific machines. APT41 has also environmentally keyed second stage malware with an RC5 key derived in part from the infected system's volume serial number.

T1484.001
Group Policy Modification
GroupAPT41

APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware.

T1486
Data Encrypted for Impact
GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

T1496.001
Compute Hijacking
GroupAPT41

APT41 deployed a Monero cryptocurrency mining tool in a victim’s environment.

T1542.003
Bootkit
GroupAPT41

APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1546.008
Accessibility Features
GroupAPT41

APT41 leveraged sticky keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT41

APT41 created and modified startup files for persistence. APT41 added a registry key in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost to establish persistence for Cobalt Strike.

T1550.002
Pass the Hash
GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

T1553.002
Code Signing
GroupAPT41

APT41 leveraged code-signing certificates to sign malware when targeting both gaming and non-gaming organizations.

T1555
Credentials from Password Stores
GroupAPT41

APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases.

T1555.003
Credentials from Web Browsers
GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

T1560.001
Archive via Utility
GroupAPT41

APT41 created a RAR archive of targeted files for exfiltration. Additionally, APT41 used the makecab.exe utility to both download tools, such as NATBypass, to the victim network and to archive a file for exfiltration.

T1566.001
Spearphishing Attachment
GroupAPT41

APT41 sent spearphishing emails with attachments such as compiled HTML (.chm) files to initially compromise their victims.

T1568.002
Domain Generation Algorithms
GroupAPT41

APT41 has used DGAs to change their C2 servers monthly.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

T1570
Lateral Tool Transfer
GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

T1574.001
DLL
GroupAPT41

APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware.

T1574.006
Dynamic Linker Hijacking
GroupAPT41

APT41 has configured payloads to load via LD_PRELOAD.

T1588.002
Tool
GroupAPT41

APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.

T1595.002
Vulnerability Scanning
GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

T1595.003
Wordlist Scanning
GroupAPT41

APT41 leverages various tools and frameworks to brute-force directories on web servers.

T1596.005
Scan Databases
GroupAPT41

APT41 uses the Chinese website fofa.su, similar to the Shodan scanning service, for passive scanning of victims.

T1599
Network Boundary Bridging
GroupAPT41

APT41 used `NATBypass` to bypass firewall restrictions and to access compromised systems via RDP.

T1684.001
Impersonation
GroupAPT41

APT41 impersonated an employee at a video game developer company to send phishing emails.

T1685
Disable or Modify Tools
GroupAPT41

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.

T1685.005
Clear Windows Event Logs
GroupAPT41

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.