Real-world descriptions of how a group, tool or campaign used a technique.
81 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
GroupVolt Typhoon | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1552 Unsecured Credentials |
GroupVolt Typhoon | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances. |
| T1552.004 Private Keys |
GroupVolt Typhoon | Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser. |
| T1555 Credentials from Password Stores |
GroupVolt Typhoon | Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY. |
| T1555.003 Credentials from Web Browsers |
GroupVolt Typhoon | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials. |
| T1560.001 Archive via Utility |
GroupVolt Typhoon | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip. |
| T1570 Lateral Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has copied web shells between servers in targeted environments. |
| T1573.001 Symmetric Cryptography |
GroupVolt Typhoon | Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications. |
| T1584.003 Virtual Private Server |
GroupVolt Typhoon | Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic. |
| T1584.004 Server |
GroupVolt Typhoon | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2. |
| T1584.005 Botnet |
GroupVolt Typhoon | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations. |
| T1584.008 Network Devices |
GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| T1587.004 Exploits |
GroupVolt Typhoon | Volt Typhoon has exploited zero-day vulnerabilities for initial access. |
| T1588.002 Tool |
GroupVolt Typhoon | Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2. |
| T1588.006 Vulnerabilities |
GroupVolt Typhoon | Volt Typhoon has used publicly available exploit code for initial access. |
| T1589 Gather Victim Identity Information |
GroupVolt Typhoon | Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance. |
| T1589.002 Email Addresses |
GroupVolt Typhoon | Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations. |
| T1590 Gather Victim Network Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network. |
| T1590.004 Network Topology |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies. |
| T1590.006 Network Security Appliances |
GroupVolt Typhoon | Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance. |
| T1591 Gather Victim Org Information |
GroupVolt Typhoon | Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization. |
| T1591.004 Identify Roles |
GroupVolt Typhoon | Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations. |
| T1592 Gather Victim Host Information |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise reconnaissance for victim host information. |
| T1593 Search Open Websites/Domains |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise web searches for victim information. |
| T1594 Search Victim-Owned Websites |
GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites. |
| T1596.005 Scan Databases |
GroupVolt Typhoon | Volt Typhoon has used FOFA, Shodan, and Censys to search for exposed victim infrastructure. |
| T1614 System Location Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system current location. |
| T1654 Log Enumeration |
GroupVolt Typhoon | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
| T1685.005 Clear Windows Event Logs |
GroupVolt Typhoon | Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.