ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1022×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupToddyCat

ToddyCat has run scripts to collect documents from targeted hosts.

T1018
Remote System Discovery
GroupToddyCat

ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery.

T1021.002
SMB/Windows Admin Shares
GroupToddyCat

ToddyCat has used locally mounted network shares for lateral movement through targated environments.

T1036.005
Match Legitimate Resource Name or Location
GroupToddyCat

ToddyCat has used the name `debug.exe` for malware components.

T1047
Windows Management Instrumentation
GroupToddyCat

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1049
System Network Connections Discovery
GroupToddyCat

ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts.

T1053.005
Scheduled Task
GroupToddyCat

ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection.

T1057
Process Discovery
GroupToddyCat

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1059.001
PowerShell
GroupToddyCat

ToddyCat has used Powershell scripts to perform post exploit collection.

T1059.003
Windows Command Shell
GroupToddyCat

ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts.

T1069.002
Domain Groups
GroupToddyCat

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1074.002
Remote Data Staging
GroupToddyCat

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

T1078.002
Domain Accounts
GroupToddyCat

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1083
File and Directory Discovery
GroupToddyCat

ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension.

T1087.002
Domain Account
GroupToddyCat

ToddyCat has run `net user %USER% /dom` for account discovery.

T1095
Non-Application Layer Protocol
GroupToddyCat

ToddyCat has used a passive backdoor that receives commands with UDP packets.

T1106
Native API
GroupToddyCat

ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts.

T1190
Exploit Public-Facing Application
GroupToddyCat

ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855) to compromise Exchange Servers at multiple organizations.

T1518.001
Security Software Discovery
GroupToddyCat

ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`.

T1560.001
Archive via Utility
GroupToddyCat

ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration.

T1564.003
Hidden Window
GroupToddyCat

ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`.

T1566.003
Spearphishing via Service
GroupToddyCat

ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram.

T1567.002
Exfiltration to Cloud Storage
GroupToddyCat

ToddyCat has used a DropBox uploader to exfiltrate stolen files.

T1680
Local Storage Discovery
GroupToddyCat

ToddyCat has collected information on bootable drives including model, vendor, and serial numbers.

T1686
Disable or Modify System Firewall
GroupToddyCat

Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.