Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupSideCopy | SideCopy has identified the IP address of a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSideCopy | SideCopy has used a legitimate DLL file name, `Duser.dll` to disguise a malicious remote access tool. |
| T1059.005 Visual Basic |
GroupSideCopy | SideCopy has sent Microsoft Office Publisher documents to victims that have embedded malicious macros that execute an hta file via calling `mshta.exe`. |
| T1082 System Information Discovery |
GroupSideCopy | SideCopy has identified the OS version of a compromised host. |
| T1105 Ingress Tool Transfer |
GroupSideCopy | SideCopy has delivered trojanized executables via spearphishing emails that contacts actor-controlled servers to download malicious payloads. |
| T1106 Native API |
GroupSideCopy | SideCopy has executed malware by calling the API function `CreateProcessW`. |
| T1204.002 Malicious File |
GroupSideCopy | SideCopy has attempted to lure victims into clicking on malicious embedded archive files sent via spearphishing campaigns. |
| T1218.005 Mshta |
GroupSideCopy | SideCopy has utilized `mshta.exe` to execute a malicious hta file. |
| T1518 Software Discovery |
GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| T1518.001 Security Software Discovery |
GroupSideCopy | SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1566.001 Spearphishing Attachment |
GroupSideCopy | SideCopy has sent spearphishing emails with malicious hta file attachments. |
| T1574.001 DLL |
GroupSideCopy | SideCopy has used a malicious loader DLL file to execute the `credwiz.exe` process and side-load the malicious payload `Duser.dll`. |
| T1584.001 Domains |
GroupSideCopy | SideCopy has compromised domains for some of their infrastructure, including for C2 and staging malware. |
| T1598.002 Spearphishing Attachment |
GroupSideCopy | SideCopy has crafted generic lures for spam campaigns to collect emails and credentials for targeting efforts. |
| T1608.001 Upload Malware |
GroupSideCopy | SideCopy has used compromised domains to host its malicious payloads. |
| T1614 System Location Discovery |
GroupSideCopy | SideCopy has identified the country location of a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.