ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0125×

44 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupHAFNIUM

HAFNIUM has used procdump to dump the LSASS process memory.

T1003.003
NTDS
GroupHAFNIUM

HAFNIUM has stolen copies of the Active Directory database (NTDS.DIT).

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1016
System Network Configuration Discovery
GroupHAFNIUM

HAFNIUM has collected IP information via IPInfo.

T1016.001
Internet Connection Discovery
GroupHAFNIUM

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

T1018
Remote System Discovery
GroupHAFNIUM

HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`.

T1033
System Owner/User Discovery
GroupHAFNIUM

HAFNIUM has used `whoami` to gather user information.

T1057
Process Discovery
GroupHAFNIUM

HAFNIUM has used `tasklist` to enumerate processes.

T1059.001
PowerShell
GroupHAFNIUM

HAFNIUM has used the Exchange Power Shell module Set-OabVirtualDirectoryPowerShell to export mailbox data.

T1059.003
Windows Command Shell
GroupHAFNIUM

HAFNIUM has used `cmd.exe` to execute commands on the victim's machine.

T1068
Exploitation for Privilege Escalation
GroupHAFNIUM

HAFNIUM has targeted unpatched applications to elevate access in targeted organizations.

T1071.001
Web Protocols
GroupHAFNIUM

HAFNIUM has used open-source C2 frameworks, including Covenant.

T1078.003
Local Accounts
GroupHAFNIUM

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

T1078.004
Cloud Accounts
GroupHAFNIUM

HAFNIUM has abused service principals in compromised environments to enable data exfiltration.

T1083
File and Directory Discovery
GroupHAFNIUM

HAFNIUM has searched file contents on a compromised host.

T1095
Non-Application Layer Protocol
GroupHAFNIUM

HAFNIUM has used TCP for C2.

T1098
Account Manipulation
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

T1105
Ingress Tool Transfer
GroupHAFNIUM

HAFNIUM has downloaded malware and tools--including Nishang and PowerCat--onto a compromised host.

T1110.003
Password Spraying
GroupHAFNIUM

HAFNIUM has gained initial access through password spray attacks.

T1114.002
Remote Email Collection
GroupHAFNIUM

HAFNIUM has used web shells and MSGraph to export mailbox data.

T1119
Automated Collection
GroupHAFNIUM

HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint.

T1132.001
Standard Encoding
GroupHAFNIUM

HAFNIUM has used ASCII encoding for C2 traffic.

T1136.002
Domain Account
GroupHAFNIUM

HAFNIUM has created domain accounts.

T1190
Exploit Public-Facing Application
GroupHAFNIUM

HAFNIUM has exploited multiple vulnerabilities to compromise edge devices and on-premises versions of Microsoft Exchange Server.

T1199
Trusted Relationship
GroupHAFNIUM

HAFNIUM has used stolen API keys and credentials associated with privilege access management (PAM), cloud app providers, and cloud data management companies to access downstream customer environments.

T1213.002
Sharepoint
GroupHAFNIUM

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint.

T1218.011
Rundll32
GroupHAFNIUM

HAFNIUM has used rundll32 to load malicious DLLs.

T1505.003
Web Shell
GroupHAFNIUM

HAFNIUM has deployed multiple web shells on compromised servers including SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy.

T1530
Data from Cloud Storage
GroupHAFNIUM

HAFNIUM has exfitrated data from OneDrive.

T1550.001
Application Access Token
GroupHAFNIUM

HAFNIUM has abused service principals with administrative permissions for data exfiltration.

T1555.006
Cloud Secrets Management Stores
GroupHAFNIUM

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults.

T1560.001
Archive via Utility
GroupHAFNIUM

HAFNIUM has used 7-Zip and WinRAR to compress stolen files for exfiltration.

T1564.001
Hidden Files and Directories
GroupHAFNIUM

HAFNIUM has hidden files on a compromised host.

T1567.002
Exfiltration to Cloud Storage
GroupHAFNIUM

HAFNIUM has exfiltrated data to file sharing sites, including MEGA.

T1583.003
Virtual Private Server
GroupHAFNIUM

HAFNIUM has operated from leased virtual private servers (VPS) in the United States.

T1583.005
Botnet
GroupHAFNIUM

HAFNIUM has incorporated leased devices into covert networks to obfuscate communications.

T1583.006
Web Services
GroupHAFNIUM

HAFNIUM has acquired web services for use in C2 and exfiltration.

T1584.005
Botnet
GroupHAFNIUM

HAFNIUM has used compromised devices in covert networks to obfuscate communications.

T1589.002
Email Addresses
GroupHAFNIUM

HAFNIUM has collected e-mail addresses for users they intended to target.

T1590
Gather Victim Network Information
GroupHAFNIUM

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment.

T1590.005
IP Addresses
GroupHAFNIUM

HAFNIUM has obtained IP addresses for publicly-accessible Exchange servers.

T1592.004
Client Configurations
GroupHAFNIUM

HAFNIUM has interacted with Office 365 tenants to gather details regarding target's environments.

T1593.003
Code Repositories
GroupHAFNIUM

HAFNIUM has discovered leaked corporate credentials on public repositories including GitHub.

T1685.005
Clear Windows Event Logs
GroupHAFNIUM

HAFNIUM has cleared actor-performed actions from logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.