ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0128×

29 examples

TechniqueUsed byProcedure example
T1012
Query Registry
GroupZIRCONIUM

ZIRCONIUM has used a tool to query the Registry for proxy settings.

T1016
System Network Configuration Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.

T1027.002
Software Packing
GroupZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.

T1033
System Owner/User Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2.

T1036
Masquerading
GroupZIRCONIUM

ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware.

T1036.004
Masquerade Task or Service
GroupZIRCONIUM

ZIRCONIUM has created a run key named Dropbox Update Setup to mask a persistence mechanism for a malicious binary.

T1041
Exfiltration Over C2 Channel
GroupZIRCONIUM

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1059.003
Windows Command Shell
GroupZIRCONIUM

ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.

T1059.006
Python
GroupZIRCONIUM

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1068
Exploitation for Privilege Escalation
GroupZIRCONIUM

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1082
System Information Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.

T1090.003
Multi-hop Proxy
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1102.002
Bidirectional Communication
GroupZIRCONIUM

ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands.

T1105
Ingress Tool Transfer
GroupZIRCONIUM

ZIRCONIUM has used tools to download malicious files to compromised hosts.

T1124
System Time Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

T1140
Deobfuscate/Decode Files or Information
GroupZIRCONIUM

ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code.

T1204.001
Malicious Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware.

T1218.007
Msiexec
GroupZIRCONIUM

ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.

T1547.001
Registry Run Keys / Startup Folder
GroupZIRCONIUM

ZIRCONIUM has created a Registry Run key named Dropbox Update Setup to establish persistence for a malicious Python binary.

T1555.003
Credentials from Web Browsers
GroupZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.

T1566.002
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to deliver malware.

T1567.002
Exfiltration to Cloud Storage
GroupZIRCONIUM

ZIRCONIUM has exfiltrated stolen data to Dropbox.

T1573.001
Symmetric Cryptography
GroupZIRCONIUM

ZIRCONIUM has used AES encrypted communications in C2.

T1583.001
Domains
GroupZIRCONIUM

ZIRCONIUM has purchased domains for use in targeted campaigns.

T1583.006
Web Services
GroupZIRCONIUM

ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.

T1584.008
Network Devices
GroupZIRCONIUM

ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks.

T1598
Phishing for Information
GroupZIRCONIUM

ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails.

T1598.003
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's.

T1665
Hide Infrastructure
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.