Real-world descriptions of how a group, tool or campaign used a technique.
44 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1003.003 NTDS |
GroupHAFNIUM | HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT). |
| T1005 Data from Local System |
GroupHAFNIUM | HAFNIUM has collected data and files from a compromised machine. |
| T1016 System Network Configuration Discovery |
GroupHAFNIUM | HAFNIUM has collected IP information via IPInfo. |
| T1016.001 Internet Connection Discovery |
GroupHAFNIUM | HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| T1018 Remote System Discovery |
GroupHAFNIUM | HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`. |
| T1033 System Owner/User Discovery |
GroupHAFNIUM | HAFNIUM has used `whoami` to gather user information. |
| T1057 Process Discovery |
GroupHAFNIUM | HAFNIUM has used `tasklist` to enumerate processes. |
| T1059.001 PowerShell |
GroupHAFNIUM | HAFNIUM has used the Exchange Power Shell module |
| T1059.003 Windows Command Shell |
GroupHAFNIUM | HAFNIUM has used `cmd.exe` to execute commands on the victim's machine. |
| T1068 Exploitation for Privilege Escalation |
GroupHAFNIUM | HAFNIUM has targeted unpatched applications to elevate access in targeted organizations. |
| T1071.001 Web Protocols |
GroupHAFNIUM | HAFNIUM has used open-source C2 frameworks, including Covenant. |
| T1078.003 Local Accounts |
GroupHAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| T1078.004 Cloud Accounts |
GroupHAFNIUM | HAFNIUM has abused service principals in compromised environments to enable data exfiltration. |
| T1083 File and Directory Discovery |
GroupHAFNIUM | HAFNIUM has searched file contents on a compromised host. |
| T1095 Non-Application Layer Protocol |
GroupHAFNIUM | HAFNIUM has used TCP for C2. |
| T1098 Account Manipulation |
GroupHAFNIUM | HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. |
| T1105 Ingress Tool Transfer |
GroupHAFNIUM | HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host. |
| T1110.003 Password Spraying |
GroupHAFNIUM | HAFNIUM has gained initial access through password spray attacks. |
| T1114.002 Remote Email Collection |
GroupHAFNIUM | HAFNIUM has used web shells and MSGraph to export mailbox data. |
| T1119 Automated Collection |
GroupHAFNIUM | HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. |
| T1132.001 Standard Encoding |
GroupHAFNIUM | HAFNIUM has used ASCII encoding for C2 traffic. |
| T1136.002 Domain Account |
GroupHAFNIUM | HAFNIUM has created domain accounts. |
| T1190 Exploit Public-Facing Application |
GroupHAFNIUM | HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server. |
| T1199 Trusted Relationship |
GroupHAFNIUM | HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments. |
| T1213.002 Sharepoint |
GroupHAFNIUM | HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint. |
| T1218.011 Rundll32 |
GroupHAFNIUM | HAFNIUM has used |
| T1505.003 Web Shell |
GroupHAFNIUM | HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. |
| T1530 Data from Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfitrated data from OneDrive. |
| T1550.001 Application Access Token |
GroupHAFNIUM | HAFNIUM has abused service principals with administrative permissions for data exfiltration. |
| T1555.006 Cloud Secrets Management Stores |
GroupHAFNIUM | HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults. |
| T1560.001 Archive via Utility |
GroupHAFNIUM | HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration. |
| T1564.001 Hidden Files and Directories |
GroupHAFNIUM | HAFNIUM has hidden files on a compromised host. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
| T1583.003 Virtual Private Server |
GroupHAFNIUM | HAFNIUM has operated from leased virtual private servers (VPS) in the United States. |
| T1583.005 Botnet |
GroupHAFNIUM | HAFNIUM has incorporated leased devices into covert networks to obfuscate communications. |
| T1583.006 Web Services |
GroupHAFNIUM | HAFNIUM has acquired web services for use in C2 and exfiltration. |
| T1584.005 Botnet |
GroupHAFNIUM | HAFNIUM has used compromised devices in covert networks to obfuscate communications. |
| T1589.002 Email Addresses |
GroupHAFNIUM | HAFNIUM has collected e-mail addresses for users they intended to target. |
| T1590 Gather Victim Network Information |
GroupHAFNIUM | HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment. |
| T1590.005 IP Addresses |
GroupHAFNIUM | HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers. |
| T1592.004 Client Configurations |
GroupHAFNIUM | HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments. |
| T1593.003 Code Repositories |
GroupHAFNIUM | HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub. |
| T1685.005 Clear Windows Event Logs |
GroupHAFNIUM | HAFNIUM has cleared actor-performed actions from logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.