ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0102×

64 examples

TechniqueUsed byProcedure example
T1553.002
Code Signing
GroupWizard Spider

Wizard Spider has used Digicert code-signing certificates for some of its malware.

T1555.004
Windows Credential Manager
GroupWizard Spider

Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupWizard Spider

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1560.001
Archive via Utility
GroupWizard Spider

Wizard Spider has archived data into ZIP files on compromised machines.

T1566.001
Spearphishing Attachment
GroupWizard Spider

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.

T1566.002
Spearphishing Link
GroupWizard Spider

Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.

T1567.002
Exfiltration to Cloud Storage
GroupWizard Spider

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1570
Lateral Tool Transfer
GroupWizard Spider

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.

T1585.002
Email Accounts
GroupWizard Spider

Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware.

T1588.002
Tool
GroupWizard Spider

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

T1588.003
Code Signing Certificates
GroupWizard Spider

Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.