Real-world descriptions of how a group, tool or campaign used a technique.
64 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupScattered Spider | Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks. |
| T1006 Direct Volume Access |
GroupScattered Spider | Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file. |
| T1016 System Network Configuration Discovery |
GroupScattered Spider | Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1018 Remote System Discovery |
GroupScattered Spider | Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure. |
| T1021.001 Remote Desktop Protocol |
GroupScattered Spider | Scattered Spider has used RDP to enable lateral movement. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1021.007 Cloud Services |
GroupScattered Spider | Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes. |
| T1041 Exfiltration Over C2 Channel |
GroupScattered Spider | Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool. |
| T1059.001 PowerShell |
GroupScattered Spider | Scattered Spider has used the PowerShell cmdlet Get-ADUser. |
| T1059.004 Unix Shell |
GroupScattered Spider | Scattered Spider has used the command shell to upload and install the Teleport remote access tool to a compromised vCenter Server Appliance. |
| T1068 Exploitation for Privilege Escalation |
GroupScattered Spider | Scattered Spider has deployed a malicious kernel driver through exploitation of CVE-2015-2291 in the Intel Ethernet diagnostics driver for Windows (iqvw64.sys). |
| T1069 Permission Groups Discovery |
GroupScattered Spider | Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| T1069.002 Domain Groups |
GroupScattered Spider | Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser. |
| T1070.008 Clear Mailbox Data |
GroupScattered Spider | Scattered Spider has manually deleted emails notifying users of suspicious account activity. |
| T1074 Data Staged |
GroupScattered Spider | Scattered Spider stages data in a centralized database prior to exfiltration. |
| T1078 Valid Accounts |
GroupScattered Spider | Scattered Spider has used compromised credentials for initial access. |
| T1078.004 Cloud Accounts |
GroupScattered Spider | Scattered Spider has used compromised Microsoft Entra ID accounts to pivot in victim environments. |
| T1082 System Information Discovery |
GroupScattered Spider | Scattered Spider has executed scripts to identify the underlying operating system to ensure it uses the correct installation package for malicious payloads. |
| T1083 File and Directory Discovery |
GroupScattered Spider | Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets. |
| T1087 Account Discovery |
GroupScattered Spider | Scattered Spider has identified vSphere administrator accounts. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1090 Proxy |
GroupScattered Spider | Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs. |
| T1098 Account Manipulation |
GroupScattered Spider | Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere. |
| T1098.003 Additional Cloud Roles |
GroupScattered Spider | Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure. |
| T1105 Ingress Tool Transfer |
GroupScattered Spider | Scattered Spider has downloaded the Teleport remote access tool to compromised VMware vCenter Servers. |
| T1114 Email Collection |
GroupScattered Spider | Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response. |
| T1114.003 Email Forwarding Rule |
GroupScattered Spider | Scattered Spider has redirected emails notifying users of suspicious account activity. |
| T1133 External Remote Services |
GroupScattered Spider | Scattered Spider has leveraged legitimate remote management tools to maintain persistent access. |
| T1136 Create Account |
GroupScattered Spider | Scattered Spider creates new user identities within the compromised organization. |
| T1204 User Execution |
GroupScattered Spider | Scattered Spider has impersonated organization IT and helpdesk staff to instruct victims to execute commercial remote access tools to gain initial access. |
| T1213.003 Code Repositories |
GroupScattered Spider | Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories. |
| T1213.005 Messaging Applications |
GroupScattered Spider | Scattered Spider threat actors search the victim’s Slack and Microsoft Teams for conversations about the intrusion and incident response. |
| T1217 Browser Information Discovery |
GroupScattered Spider | Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer. |
| T1219.002 Remote Desktop Software |
GroupScattered Spider | In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network. |
| T1484.002 Trust Modification |
GroupScattered Spider | Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1490 Inhibit System Recovery |
GroupScattered Spider | Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts. |
| T1530 Data from Cloud Storage |
GroupScattered Spider | Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes. |
| T1538 Cloud Service Dashboard |
GroupScattered Spider | Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement. |
| T1539 Steal Web Session Cookie |
GroupScattered Spider | Scattered Spider retrieves browser cookies via Raccoon Stealer. |
| T1543.002 Systemd Service |
GroupScattered Spider | Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/ |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1552.004 Private Keys |
GroupScattered Spider | Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host. |
| T1553.002 Code Signing |
GroupScattered Spider | Scattered Spider has used self-signed and stolen certificates originally issued to NVIDIA and Global Software LLC. |
| T1555.005 Password Managers |
GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| T1556.006 Multi-Factor Authentication |
GroupScattered Spider | After compromising user accounts, Scattered Spider registers their own MFA tokens. |
| T1556.009 Conditional Access Policies |
GroupScattered Spider | Scattered Spider has added additional trusted locations to Azure AD conditional access policies. |
| T1564.008 Email Hiding Rules |
GroupScattered Spider | Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products. |
| T1567.002 Exfiltration to Cloud Storage |
GroupScattered Spider | Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets. |
| T1572 Protocol Tunneling |
GroupScattered Spider | Scattered Spider has installed protocol-tunneling tools on VMware vCenter and adversary-controlled VMs, including Teleport.sh, Chisel (configured to communicate with trycloudflare[.]com subdomains), MobaXterm, ngrok, Pinggy, and Teleport. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.