ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0129×

85 examples

TechniqueUsed byProcedure example
T1218.004
InstallUtil
GroupMustang Panda

Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager.

T1218.005
Mshta
GroupMustang Panda

Mustang Panda has used mshta.exe to launch collection scripts.

T1219.001
IDE Tunneling
GroupMustang Panda

Mustang Panda has utilized an established Github account to create a tunnel within the victim environment using Visual Studio Code through the `code.exe tunnel` command.

T1219.002
Remote Desktop Software
GroupMustang Panda

Mustang Panda has installed TeamViewer on targeted systems.

T1505.003
Web Shell
GroupMustang Panda

Mustang Panda has used China Chopper web shells to maintain access to victims’ environments.

T1518
Software Discovery
GroupMustang Panda

Mustang Panda has searched the victim system for the InstallUtil.exe program and its version.

T1546.003
Windows Management Instrumentation Event Subscription
GroupMustang Panda

Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupMustang Panda

Mustang Panda has created the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\AdobelmdyU to maintain persistence. Mustang Panda has also established persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1557
Adversary-in-the-Middle
GroupMustang Panda

Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1560.003
Archive via Custom Method
GroupMustang Panda

Mustang Panda has encrypted documents with RC4 prior to exfiltration.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

T1566.001
Spearphishing Attachment
GroupMustang Panda

Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs.

T1566.002
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupMustang Panda

Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`.

T1572
Protocol Tunneling
GroupMustang Panda

Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445.

T1573.001
Symmetric Cryptography
GroupMustang Panda

Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.005
Executable Installer File Permissions Weakness
GroupMustang Panda

Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

T1583.006
Web Services
GroupMustang Panda

Mustang Panda has set up Dropbox and Google Drive to host malicious downloads.

T1585.002
Email Accounts
GroupMustang Panda

Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail.

T1586.002
Email Accounts
GroupMustang Panda

Mustang Panda has compromised legitimate email accounts to use in their spear-phishing operations.

T1587.001
Malware
GroupMustang Panda

Mustang Panda has developed custom malware for use in their operations.

T1588.002
Tool
GroupMustang Panda

Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities.

T1588.003
Code Signing Certificates
GroupMustang Panda

Mustang Panda has used revoked code signing certificates for its malicious payloads.

T1588.004
Digital Certificates
GroupMustang Panda

Mustang Panda has obtained SSL certificates for their C2 domains.

T1593
Search Open Websites/Domains
GroupMustang Panda

Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments.

T1598.003
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered web bugs to profile their intended targets.

T1608
Stage Capabilities
GroupMustang Panda

Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims.

T1608.001
Upload Malware
GroupMustang Panda

Mustang Panda has hosted malicious payloads on DropBox including PlugX.

T1622
Debugger Evasion
GroupMustang Panda

Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.

T1654
Log Enumeration
GroupMustang Panda

Mustang Panda has used Wevtutil to gather Windows Security Event Logs.

T1678
Delay Execution
GroupMustang Panda

Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.