ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1012×

19 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupCURIUM

CURIUM has exfiltrated data from a compromised machine.

T1041
Exfiltration Over C2 Channel
GroupCURIUM

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupCURIUM

CURIUM has used SMTPS to exfiltrate collected data from victims.

T1059.001
PowerShell
GroupCURIUM

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.

T1082
System Information Discovery
GroupCURIUM

CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information.

T1124
System Time Discovery
GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1189
Drive-by Compromise
GroupCURIUM

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1204.002
Malicious File
GroupCURIUM

CURIUM has lured users into opening malicious files delivered via social media.

T1505.003
Web Shell
GroupCURIUM

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

T1566.001
Spearphishing Attachment
GroupCURIUM

CURIUM has used phishing with malicious attachments for initial access to victim environments.

T1566.003
Spearphishing via Service
GroupCURIUM

CURIUM has used social media to deliver malicious files to victims.

T1583.001
Domains
GroupCURIUM

CURIUM created domains to facilitate strategic website compromise and credential capture activities.

T1583.003
Virtual Private Server
GroupCURIUM

CURIUM created virtual private server instances to facilitate use of malicious domains and other items.

T1583.004
Server
GroupCURIUM

CURIUM has created dedicated servers for command and control and exfiltration purposes.

T1584.006
Web Services
GroupCURIUM

CURIUM has compromised legitimate websites to enable strategic website compromise attacks.

T1585.001
Social Media Accounts
GroupCURIUM

CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman.

T1585.002
Email Accounts
GroupCURIUM

CURIUM has created dedicated email accounts for use with tools such as IMAPLoader.

T1598.003
Spearphishing Link
GroupCURIUM

CURIUM used malicious links to adversary-controlled resources for credential harvesting.

T1608.004
Drive-by Target
GroupCURIUM

CURIUM used strategic website compromise to fingerprint then target victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.