ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0139×

56 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
GroupTeamTNT

TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them.

T1014
Rootkit
GroupTeamTNT

TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine.

T1016
System Network Configuration Discovery
GroupTeamTNT

TeamTNT has enumerated the host machine’s IP address.

T1021.004
SSH
GroupTeamTNT

TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them.

T1027.002
Software Packing
GroupTeamTNT

TeamTNT has used UPX and Ezuri packer to pack its binaries.

T1027.013
Encrypted/Encoded File
GroupTeamTNT

TeamTNT has encrypted its binaries via AES and encoded files using Base64.

T1036
Masquerading
GroupTeamTNT

TeamTNT has disguised their scripts with docker-related file names.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamTNT

TeamTNT has replaced .dockerd and .dockerenv with their own scripts and cryptocurrency mining software.

T1046
Network Service Discovery
GroupTeamTNT

TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments.

T1048
Exfiltration Over Alternative Protocol
GroupTeamTNT

TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL.

T1049
System Network Connections Discovery
GroupTeamTNT

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1057
Process Discovery
GroupTeamTNT

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1059.001
PowerShell
GroupTeamTNT

TeamTNT has executed PowerShell commands in batch scripts.

T1059.003
Windows Command Shell
GroupTeamTNT

TeamTNT has used batch scripts to download tools and executing cryptocurrency miners.

T1059.004
Unix Shell
GroupTeamTNT

TeamTNT has used shell scripts for execution.

T1059.009
Cloud API
GroupTeamTNT

TeamTNT has leveraged AWS CLI to enumerate cloud environments with compromised credentials.

T1059.013
Container CLI/API
GroupTeamTNT

TeamTNT targeted misconfigured containers and used container CLI tools.

T1070.003
Clear Command History
GroupTeamTNT

TeamTNT has cleared command history with history -c.

T1070.004
File Deletion
GroupTeamTNT

TeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them.

T1071
Application Layer Protocol
GroupTeamTNT

TeamTNT has used an IRC bot for C2 communications.

T1071.001
Web Protocols
GroupTeamTNT

TeamTNT has the `curl` command to send credentials over HTTP and the `curl` and `wget` commands to download new software. TeamTNT has also used a custom user agent HTTP header in shell scripts.

T1074.001
Local Data Staging
GroupTeamTNT

TeamTNT has aggregated collected credentials in text files before exfiltrating.

T1082
System Information Discovery
GroupTeamTNT

TeamTNT has searched for system version, architecture, and hostname information.

T1083
File and Directory Discovery
GroupTeamTNT

TeamTNT has used a script that checks `/proc/*/environ` for environment variables related to AWS.

T1098.004
SSH Authorized Keys
GroupTeamTNT

TeamTNT has added RSA keys in authorized_keys.

T1102
Web Service
GroupTeamTNT

TeamTNT has leveraged iplogger.org to send collected data back to C2.

T1105
Ingress Tool Transfer
GroupTeamTNT

TeamTNT has the curl and wget commands as well as batch scripts to download new tools.

T1120
Peripheral Device Discovery
GroupTeamTNT

TeamTNT has searched for attached VGA devices using lspci.

T1133
External Remote Services
GroupTeamTNT

TeamTNT has used open-source tools such as Weave Scope to target exposed Docker API ports and gain initial access to victim environments. TeamTNT has also targeted exposed kubelets for Kubernetes environments.

T1136.001
Local Account
GroupTeamTNT

TeamTNT has created local privileged users on victim machines.

T1140
Deobfuscate/Decode Files or Information
GroupTeamTNT

TeamTNT has used a script that decodes a Base64-encoded version of WeaveWorks Scope.

T1204.003
Malicious Image
GroupTeamTNT

TeamTNT has relied on users to download and execute malicious Docker images.

T1219
Remote Access Tools
GroupTeamTNT

TeamTNT has established tmate sessions for C2 communications.

T1222.002
Linux and Mac Permissions
GroupTeamTNT

TeamTNT has modified the permissions on binaries with chattr.

T1496.001
Compute Hijacking
GroupTeamTNT

TeamTNT has deployed XMRig Docker images to mine cryptocurrency. TeamTNT has also infected Docker containers and Kubernetes clusters with XMRig, and used RainbowMiner and lolMiner for mining cryptocurrency.

T1518.001
Security Software Discovery
GroupTeamTNT

TeamTNT has searched for security products on infected machines.

T1543.002
Systemd Service
GroupTeamTNT

TeamTNT has established persistence through the creation of a cryptocurrency mining system service using systemctl.

T1543.003
Windows Service
GroupTeamTNT

TeamTNT has used malware that adds cryptocurrency miners as a service.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamTNT

TeamTNT has added batch scripts to the startup folder.

T1552.001
Credentials In Files
GroupTeamTNT

TeamTNT has searched for unsecured AWS credentials and Docker API credentials.

T1552.004
Private Keys
GroupTeamTNT

TeamTNT has searched for unsecured SSH keys.

T1552.005
Cloud Instance Metadata API
GroupTeamTNT

TeamTNT has queried the AWS instance metadata service for credentials.

T1569.003
Systemctl
GroupTeamTNT

TeamTNT has created system services to execute cryptocurrency mining software.

T1583.001
Domains
GroupTeamTNT

TeamTNT has obtained domains to host their payloads.

T1587.001
Malware
GroupTeamTNT

TeamTNT has developed custom malware such as Hildegard.

T1595.001
Scanning IP Blocks
GroupTeamTNT

TeamTNT has scanned specific lists of target IP addresses.

T1595.002
Vulnerability Scanning
GroupTeamTNT

TeamTNT has scanned for vulnerabilities in IoT devices and other related resources such as the Docker API.

T1608.001
Upload Malware
GroupTeamTNT

TeamTNT has uploaded backdoored Docker images to Docker Hub.

T1609
Container Administration Command
GroupTeamTNT

TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers.

T1610
Deploy Container
GroupTeamTNT

TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.