Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003.001 LSASS Memory |
GroupEmber Bear | Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.002 Security Account Manager |
GroupEmber Bear | Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.004 LSA Secrets |
GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1005 Data from Local System |
GroupEmber Bear | Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1018 Remote System Discovery |
GroupEmber Bear | Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery. |
| T1021 Remote Services |
GroupEmber Bear | Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so. |
| T1036 Masquerading |
GroupEmber Bear | Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEmber Bear | Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1046 Network Service Discovery |
GroupEmber Bear | Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments. |
| T1047 Windows Management Instrumentation |
GroupEmber Bear | Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1053.005 Scheduled Task |
GroupEmber Bear | Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines. |
| T1059.001 PowerShell |
GroupEmber Bear | Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1070.004 File Deletion |
GroupEmber Bear | Ember Bear deletes files related to lateral movement to avoid detection. |
| T1071.004 DNS |
GroupEmber Bear | Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes. |
| T1078.001 Default Accounts |
GroupEmber Bear | Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access. |
| T1090.003 Multi-hop Proxy |
GroupEmber Bear | Ember Bear has configured multi-hop proxies via ProxyChains within victim environments. |
| T1095 Non-Application Layer Protocol |
GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| T1110 Brute Force |
GroupEmber Bear | Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command. |
| T1110.003 Password Spraying |
GroupEmber Bear | Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords. |
| T1112 Modify Registry |
GroupEmber Bear | Ember Bear modifies registry values for anti-forensics and defense evasion purposes. |
| T1114 Email Collection |
GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| T1119 Automated Collection |
GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| T1125 Video Capture |
GroupEmber Bear | Ember Bear has exfiltrated images from compromised IP cameras. |
| T1133 External Remote Services |
GroupEmber Bear | Ember Bear have used VPNs both for initial access to victim environments and for persistence within them following compromise. |
| T1190 Exploit Public-Facing Application |
GroupEmber Bear | Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems. |
| T1195 Supply Chain Compromise |
GroupEmber Bear | Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations. |
| T1203 Exploitation for Client Execution |
GroupEmber Bear | Ember Bear has used exploits to enable follow-on execution of frameworks such as Meterpreter. |
| T1210 Exploitation of Remote Services |
GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| T1491.002 External Defacement |
GroupEmber Bear | Ember Bear is linked to the defacement of several Ukrainian organization websites. |
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1550.002 Pass the Hash |
GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| T1552.001 Credentials In Files |
GroupEmber Bear | Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials. |
| T1560 Archive Collected Data |
GroupEmber Bear | Ember Bear has compressed collected data prior to exfiltration. |
| T1561.002 Disk Structure Wipe |
GroupEmber Bear | Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| T1570 Lateral Tool Transfer |
GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| T1571 Non-Standard Port |
GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| T1572 Protocol Tunneling |
GroupEmber Bear | Ember Bear has used ProxyChains to tunnel protocols to internal networks. |
| T1583 Acquire Infrastructure |
GroupEmber Bear | Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations. |
| T1583.003 Virtual Private Server |
GroupEmber Bear | Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration. |
| T1585 Establish Accounts |
GroupEmber Bear | Ember Bear has created accounts on dark web forums to obtain various tools and malware. |
| T1588.001 Malware |
GroupEmber Bear | Ember Bear has acquired malware and related tools from dark web forums. |
| T1588.005 Exploits |
GroupEmber Bear | Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories. |
| T1595.001 Scanning IP Blocks |
GroupEmber Bear | Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations. |
| T1595.002 Vulnerability Scanning |
GroupEmber Bear | Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure. |
| T1654 Log Enumeration |
GroupEmber Bear | Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.