ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1018×

28 examples

TechniqueUsed byProcedure example
T1016.001
Internet Connection Discovery
GroupTA2541

TA2541 has run scripts to check internet connectivity from compromised hosts.

T1027.002
Software Packing
GroupTA2541

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.013
Encrypted/Encoded File
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.015
Compression
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1036.005
Match Legitimate Resource Name or Location
GroupTA2541

TA2541 has used file names to mimic legitimate Windows files or system functionality.

T1047
Windows Management Instrumentation
GroupTA2541

TA2541 has used WMI to query targeted systems for security products.

T1053.005
Scheduled Task
GroupTA2541

TA2541 has used scheduled tasks to establish persistence for installed tools.

T1055
Process Injection
GroupTA2541

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1055.012
Process Hollowing
GroupTA2541

TA2541 has used process hollowing to execute CyberGate malware.

T1059.001
PowerShell
GroupTA2541

TA2541 has used PowerShell to download files and to inject into various Windows processes.

T1059.005
Visual Basic
GroupTA2541

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1082
System Information Discovery
GroupTA2541

TA2541 has collected system information prior to downloading malware on the targeted host.

T1105
Ingress Tool Transfer
GroupTA2541

TA2541 has used malicious scripts and macros with the ability to download additional payloads.

T1204.001
Malicious Link
GroupTA2541

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.002
Malicious File
GroupTA2541

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

T1218.005
Mshta
GroupTA2541

TA2541 has used `mshta` to execute scripts including VBS.

T1518.001
Security Software Discovery
GroupTA2541

TA2541 has used tools to search victim systems for security products such as antivirus and firewall software.

T1547.001
Registry Run Keys / Startup Folder
GroupTA2541

TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads.

T1566.001
Spearphishing Attachment
GroupTA2541

TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents.

T1566.002
Spearphishing Link
GroupTA2541

TA2541 has used spearphishing e-mails with malicious links to deliver malware.

T1568
Dynamic Resolution
GroupTA2541

TA2541 has used dynamic DNS services for C2 infrastructure.

T1573.002
Asymmetric Cryptography
GroupTA2541

TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT.

T1583.001
Domains
GroupTA2541

TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom.

T1583.006
Web Services
GroupTA2541

TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub.

T1588.001
Malware
GroupTA2541

TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories.

T1588.002
Tool
GroupTA2541

TA2541 has used commodity remote access tools.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

T1685
Disable or Modify Tools
GroupTA2541

TA2541 has attempted to disable built-in security protections such as Windows AMSI.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.