ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1014×

28 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1030
Data Transfer Size Limits
GroupLuminousMoth

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

T1033
System Owner/User Discovery
GroupLuminousMoth

LuminousMoth has used a malicious DLL to collect the username from compromised hosts.

T1036.005
Match Legitimate Resource Name or Location
GroupLuminousMoth

LuminousMoth has disguised their exfiltration malware as `ZoomVideoApp.exe`.

T1041
Exfiltration Over C2 Channel
GroupLuminousMoth

LuminousMoth has used malware that exfiltrates stolen data to its C2 server.

T1053.005
Scheduled Task
GroupLuminousMoth

LuminousMoth has created scheduled tasks to establish persistence for their tools.

T1071.001
Web Protocols
GroupLuminousMoth

LuminousMoth has used HTTP for C2.

T1083
File and Directory Discovery
GroupLuminousMoth

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1091
Replication Through Removable Media
GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1105
Ingress Tool Transfer
GroupLuminousMoth

LuminousMoth has downloaded additional malware and tools onto a compromised host.

T1112
Modify Registry
GroupLuminousMoth

LuminousMoth has used malware that adds Registry keys for persistence.

T1204.001
Malicious Link
GroupLuminousMoth

LuminousMoth has lured victims into clicking malicious Dropbox download links delivered through spearphishing.

T1539
Steal Web Session Cookie
GroupLuminousMoth

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

T1547.001
Registry Run Keys / Startup Folder
GroupLuminousMoth

LuminousMoth has used malicious DLLs that setup persistence in the Registry Key `HKCU\Software\Microsoft\Windows\Current Version\Run`.

T1553.002
Code Signing
GroupLuminousMoth

LuminousMoth has signed their malware with a valid digital signature.

T1557.002
ARP Cache Poisoning
GroupLuminousMoth

LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website.

T1560
Archive Collected Data
GroupLuminousMoth

LuminousMoth has manually archived stolen files from victim machines before exfiltration.

T1564.001
Hidden Files and Directories
GroupLuminousMoth

LuminousMoth has used malware to store malicious binaries in hidden directories on victim's USB drives.

T1566.002
Spearphishing Link
GroupLuminousMoth

LuminousMoth has sent spearphishing emails containing a malicious Dropbox download link.

T1567.002
Exfiltration to Cloud Storage
GroupLuminousMoth

LuminousMoth has exfiltrated data to Google Drive.

T1574.001
DLL
GroupLuminousMoth

LuminousMoth has used legitimate executables such as `winword.exe` and `igfxem.exe` to side-load their malware.

T1587.001
Malware
GroupLuminousMoth

LuminousMoth has used unique malware for information theft and exfiltration.

T1588.001
Malware
GroupLuminousMoth

LuminousMoth has obtained and used malware such as Cobalt Strike.

T1588.002
Tool
GroupLuminousMoth

LuminousMoth has obtained an ARP spoofing tool from GitHub.

T1588.004
Digital Certificates
GroupLuminousMoth

LuminousMoth has used a valid digital certificate for some of their malware.

T1608.001
Upload Malware
GroupLuminousMoth

LuminousMoth has hosted malicious payloads on Dropbox.

T1608.004
Drive-by Target
GroupLuminousMoth

LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection.

T1608.005
Link Target
GroupLuminousMoth

LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.