Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupLazyScripter | LazyScripter has leveraged the BatchEncryption tool to perform advanced batch script obfuscation and encoding techniques. |
| T1036 Masquerading |
GroupLazyScripter | LazyScripter has used several different security software icons to disguise executables. |
| T1059.001 PowerShell |
GroupLazyScripter | LazyScripter has used PowerShell scripts to execute malicious code. |
| T1059.003 Windows Command Shell |
GroupLazyScripter | LazyScripter has used batch files to deploy open-source and multi-stage RATs. |
| T1059.005 Visual Basic |
GroupLazyScripter | LazyScripter has used VBScript to execute malicious code. |
| T1059.007 JavaScript |
GroupLazyScripter | LazyScripter has used JavaScript in its attacks. |
| T1071.004 DNS |
GroupLazyScripter | LazyScripter has leveraged dynamic DNS providers for C2 communications. |
| T1102 Web Service |
GroupLazyScripter | LazyScripter has used GitHub to host its payloads to operate spam campaigns. |
| T1105 Ingress Tool Transfer |
GroupLazyScripter | LazyScripter had downloaded additional tools to a compromised host. |
| T1204.001 Malicious Link |
GroupLazyScripter | LazyScripter has relied upon users clicking on links to malicious files. |
| T1204.002 Malicious File |
GroupLazyScripter | LazyScripter has lured users to open malicious email attachments. |
| T1218.005 Mshta |
GroupLazyScripter | LazyScripter has used `mshta.exe` to execute Koadic stagers. |
| T1218.011 Rundll32 |
GroupLazyScripter | LazyScripter has used `rundll32.exe` to execute Koadic stagers. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazyScripter | LazyScripter has achieved persistence via writing a PowerShell script to the autorun registry key. |
| T1566.001 Spearphishing Attachment |
GroupLazyScripter | LazyScripter has used spam emails weaponized with archive or document files as its initial infection vector. |
| T1566.002 Spearphishing Link |
GroupLazyScripter | LazyScripter has used spam emails that contain a link that redirects the victim to download a malicious document. |
| T1583.001 Domains |
GroupLazyScripter | LazyScripter has used dynamic DNS providers to create legitimate-looking subdomains for C2. |
| T1583.006 Web Services |
GroupLazyScripter | LazyScripter has established GitHub accounts to host its toolsets. |
| T1588.001 Malware |
GroupLazyScripter | LazyScripter has used a variety of open-source remote access Trojans for its operations. |
| T1608.001 Upload Malware |
GroupLazyScripter | LazyScripter has hosted open-source remote access Trojans used in its operations in GitHub. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.