ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1024×

17 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupAkira

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.

T1021.001
Remote Desktop Protocol
GroupAkira

Akira has used RDP for lateral movement.

T1027.001
Binary Padding
GroupAkira

Akira has used binary padding to obfuscate payloads.

T1036.005
Match Legitimate Resource Name or Location
GroupAkira

Akira has used legitimate names and locations for files to evade defenses.

T1059.001
PowerShell
GroupAkira

Akira has used PowerShell scripts for credential harvesting and privilege escalation.

T1078
Valid Accounts
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1133
External Remote Services
GroupAkira

Akira uses compromised VPN accounts for initial access to victim networks.

T1213.002
Sharepoint
GroupAkira

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

T1219
Remote Access Tools
GroupAkira

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.

T1482
Domain Trust Discovery
GroupAkira

Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments.

T1486
Data Encrypted for Impact
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

T1531
Account Access Removal
GroupAkira

Akira deletes administrator accounts in victim networks prior to encryption.

T1558
Steal or Forge Kerberos Tickets
GroupAkira

Akira have used scripts to dump Kerberos authentication credentials.

T1560.001
Archive via Utility
GroupAkira

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

T1657
Financial Theft
GroupAkira

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.

T1685
Disable or Modify Tools
GroupAkira

Akira has disabled or modified security tools for defense evasion.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.