Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupZIRCONIUM | ZIRCONIUM has used a tool to query the Registry for proxy settings. |
| T1016 System Network Configuration Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1027.002 Software Packing |
GroupZIRCONIUM | ZIRCONIUM has used multi-stage packers for exploit code. |
| T1033 System Owner/User Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2. |
| T1036 Masquerading |
GroupZIRCONIUM | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1036.004 Masquerade Task or Service |
GroupZIRCONIUM | ZIRCONIUM has created a run key named |
| T1041 Exfiltration Over C2 Channel |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1059.003 Windows Command Shell |
GroupZIRCONIUM | ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1068 Exploitation for Privilege Escalation |
GroupZIRCONIUM | ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation. |
| T1082 System Information Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2. |
| T1090.003 Multi-hop Proxy |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1105 Ingress Tool Transfer |
GroupZIRCONIUM | ZIRCONIUM has used tools to download malicious files to compromised hosts. |
| T1124 System Time Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
| T1140 Deobfuscate/Decode Files or Information |
GroupZIRCONIUM | ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code. |
| T1204.001 Malicious Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware. |
| T1218.007 Msiexec |
GroupZIRCONIUM | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupZIRCONIUM | ZIRCONIUM has created a Registry Run key named |
| T1555.003 Credentials from Web Browsers |
GroupZIRCONIUM | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated stolen data to Dropbox. |
| T1573.001 Symmetric Cryptography |
GroupZIRCONIUM | ZIRCONIUM has used AES encrypted communications in C2. |
| T1583.001 Domains |
GroupZIRCONIUM | ZIRCONIUM has purchased domains for use in targeted campaigns. |
| T1583.006 Web Services |
GroupZIRCONIUM | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails. |
| T1584.008 Network Devices |
GroupZIRCONIUM | ZIRCONIUM has compromised network devices such as small office and home office (SOHO) routers and IoT devices for ORB (operational relay box) Proxy networks. |
| T1598 Phishing for Information |
GroupZIRCONIUM | ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails. |
| T1598.003 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's. |
| T1665 Hide Infrastructure |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.