ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0140×

20 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupLazyScripter

LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques.

T1036
Masquerading
GroupLazyScripter

LazyScripter has used several different security software icons to disguise executables.

T1059.001
PowerShell
GroupLazyScripter

LazyScripter has used PowerShell scripts to execute malicious code.

T1059.003
Windows Command Shell
GroupLazyScripter

LazyScripter has used batch files to deploy open-source and multi-stage RATs.

T1059.005
Visual Basic
GroupLazyScripter

LazyScripter has used VBScript to execute malicious code.

T1059.007
JavaScript
GroupLazyScripter

LazyScripter has used JavaScript in its attacks.

T1071.004
DNS
GroupLazyScripter

LazyScripter has leveraged dynamic DNS providers for C2 communications.

T1102
Web Service
GroupLazyScripter

LazyScripter has used GitHub to host its payloads to operate spam campaigns.

T1105
Ingress Tool Transfer
GroupLazyScripter

LazyScripter had downloaded additional tools to a compromised host.

T1204.001
Malicious Link
GroupLazyScripter

LazyScripter has relied upon users clicking on links to malicious files.

T1204.002
Malicious File
GroupLazyScripter

LazyScripter has lured users to open malicious email attachments.

T1218.005
Mshta
GroupLazyScripter

LazyScripter has used `mshta.exe` to execute Koadic stagers.

T1218.011
Rundll32
GroupLazyScripter

LazyScripter has used `rundll32.exe` to execute Koadic stagers.

T1547.001
Registry Run Keys / Startup Folder
GroupLazyScripter

LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key.

T1566.001
Spearphishing Attachment
GroupLazyScripter

LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector.

T1566.002
Spearphishing Link
GroupLazyScripter

LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document.

T1583.001
Domains
GroupLazyScripter

LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2.

T1583.006
Web Services
GroupLazyScripter

LazyScripter has established GitHub accounts to host its toolsets.

T1588.001
Malware
GroupLazyScripter

LazyScripter has used a variety of open-source remote access Trojans for its operations.

T1608.001
Upload Malware
GroupLazyScripter

LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.