Real-world descriptions of how a group, tool or campaign used a technique.
64 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.002 Code Signing |
GroupWizard Spider | Wizard Spider has used Digicert code-signing certificates for some of its malware. |
| T1555.004 Windows Credential Manager |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupWizard Spider | Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1560.001 Archive via Utility |
GroupWizard Spider | Wizard Spider has archived data into ZIP files on compromised machines. |
| T1566.001 Spearphishing Attachment |
GroupWizard Spider | Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1566.002 Spearphishing Link |
GroupWizard Spider | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services. |
| T1567.002 Exfiltration to Cloud Storage |
GroupWizard Spider | Wizard Spider has exfiltrated stolen victim data to various cloud storage providers. |
| T1569.002 Service Execution |
GroupWizard Spider | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network. |
| T1570 Lateral Tool Transfer |
GroupWizard Spider | Wizard Spider has used stolen credentials to copy tools into the |
| T1585.002 Email Accounts |
GroupWizard Spider | Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware. |
| T1588.002 Tool |
GroupWizard Spider | Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts. |
| T1588.003 Code Signing Certificates |
GroupWizard Spider | Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.