ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1015×

64 examples

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1006
Direct Volume Access
GroupScattered Spider

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

T1016
System Network Configuration Discovery
GroupScattered Spider

Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`.

T1018
Remote System Discovery
GroupScattered Spider

Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.

T1021.001
Remote Desktop Protocol
GroupScattered Spider

Scattered Spider has used RDP to enable lateral movement.

T1021.004
SSH
GroupScattered Spider

Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI.

T1021.007
Cloud Services
GroupScattered Spider

Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes.

T1041
Exfiltration Over C2 Channel
GroupScattered Spider

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1059.001
PowerShell
GroupScattered Spider

Scattered Spider has used the PowerShell cmdlet Get-ADUser.

T1059.004
Unix Shell
GroupScattered Spider

Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance.

T1068
Exploitation for Privilege Escalation
GroupScattered Spider

Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys).

T1069
Permission Groups Discovery
GroupScattered Spider

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1070.008
Clear Mailbox Data
GroupScattered Spider

Scattered Spider has manually deleted emails notifying users of suspicious account activity.

T1074
Data Staged
GroupScattered Spider

Scattered Spider stages data in a centralized database prior to exfiltration.

T1078
Valid Accounts
GroupScattered Spider

Scattered Spider has used compromised credentials for initial access.

T1078.004
Cloud Accounts
GroupScattered Spider

Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments.

T1082
System Information Discovery
GroupScattered Spider

Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1087
Account Discovery
GroupScattered Spider

Scattered Spider has identified vSphere administrator accounts.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1098
Account Manipulation
GroupScattered Spider

Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere.

T1098.003
Additional Cloud Roles
GroupScattered Spider

Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure.

T1105
Ingress Tool Transfer
GroupScattered Spider

Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers.

T1114
Email Collection
GroupScattered Spider

Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response.

T1114.003
Email Forwarding Rule
GroupScattered Spider

Scattered Spider has redirected emails notifying users of suspicious account activity.

T1133
External Remote Services
GroupScattered Spider

Scattered Spider has leveraged legitimate remote management tools to maintain persistent access.

T1136
Create Account
GroupScattered Spider

Scattered Spider creates new user identities within the compromised organization.

T1204
User Execution
GroupScattered Spider

Scattered Spider has impersonated organization IT and helpdesk staff to instruct victims to execute commercial remote access tools to gain initial access.

T1213.003
Code Repositories
GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

T1213.005
Messaging Applications
GroupScattered Spider

Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response.

T1217
Browser Information Discovery
GroupScattered Spider

Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer.

T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1484.002
Trust Modification
GroupScattered Spider

Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1490
Inhibit System Recovery
GroupScattered Spider

Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.

T1530
Data from Cloud Storage
GroupScattered Spider

Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes.

T1538
Cloud Service Dashboard
GroupScattered Spider

Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement.

T1539
Steal Web Session Cookie
GroupScattered Spider

Scattered Spider retrieves browser cookies via Raccoon Stealer.

T1543.002
Systemd Service
GroupScattered Spider

Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/
system/teleport.service` to establish persistence for the Teleport remote access tool.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1552.004
Private Keys
GroupScattered Spider

Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host.

T1553.002
Code Signing
GroupScattered Spider

Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC.

T1555.005
Password Managers
GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

T1556.006
Multi-Factor Authentication
GroupScattered Spider

After compromising user accounts, Scattered Spider registers their own MFA tokens.

T1556.009
Conditional Access Policies
GroupScattered Spider

Scattered Spider has added additional trusted locations to Azure AD conditional access policies.

T1564.008
Email Hiding Rules
GroupScattered Spider

Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1572
Protocol Tunneling
GroupScattered Spider

Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.