Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupBITTER | BITTER has used a RAR SFX dropper to deliver malware. |
| T1036.004 Masquerade Task or Service |
GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| T1053.005 Scheduled Task |
GroupBITTER | BITTER has used scheduled tasks for persistence and execution. |
| T1068 Exploitation for Privilege Escalation |
GroupBITTER | BITTER has exploited CVE-2021-1732 for privilege escalation. |
| T1071.001 Web Protocols |
GroupBITTER | BITTER has used HTTP POST requests for C2. |
| T1095 Non-Application Layer Protocol |
GroupBITTER | BITTER has used TCP for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupBITTER | BITTER has downloaded additional malware and tools onto a compromised host. |
| T1203 Exploitation for Client Execution |
GroupBITTER | BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. |
| T1204.002 Malicious File |
GroupBITTER | BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing. |
| T1559.002 Dynamic Data Exchange |
GroupBITTER | BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads. |
| T1566.001 Spearphishing Attachment |
GroupBITTER | BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet. |
| T1568 Dynamic Resolution |
GroupBITTER | BITTER has used DDNS for C2 communications. |
| T1573 Encrypted Channel |
GroupBITTER | BITTER has encrypted their C2 communications. |
| T1583.001 Domains |
GroupBITTER | BITTER has registered a variety of domains to host malicious payloads and for C2. |
| T1588.002 Tool |
GroupBITTER | BITTER has obtained tools such as PuTTY for use in their operations. |
| T1608.001 Upload Malware |
GroupBITTER | BITTER has registered domains to stage payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.