Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupAkira | Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks. |
| T1021.001 Remote Desktop Protocol |
GroupAkira | Akira has used RDP for lateral movement. |
| T1027.001 Binary Padding |
GroupAkira | Akira has used binary padding to obfuscate payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAkira | Akira has used legitimate names and locations for files to evade defenses. |
| T1059.001 PowerShell |
GroupAkira | Akira has used PowerShell scripts for credential harvesting and privilege escalation. |
| T1078 Valid Accounts |
GroupAkira | Akira uses valid account information to remotely access victim networks, such as VPN credentials. |
| T1133 External Remote Services |
GroupAkira | Akira uses compromised VPN accounts for initial access to victim networks. |
| T1213.002 Sharepoint |
GroupAkira | Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity. |
| T1219 Remote Access Tools |
GroupAkira | Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. |
| T1482 Domain Trust Discovery |
GroupAkira | Akira uses the built-in Nltest utility or tools such as AdFind to enumerate Active Directory trusts in victim environments. |
| T1486 Data Encrypted for Impact |
GroupAkira | Akira encrypts files in victim environments as part of ransomware operations. |
| T1531 Account Access Removal |
GroupAkira | Akira deletes administrator accounts in victim networks prior to encryption. |
| T1558 Steal or Forge Kerberos Tickets |
GroupAkira | Akira have used scripts to dump Kerberos authentication credentials. |
| T1560.001 Archive via Utility |
GroupAkira | Akira uses utilities such as WinRAR to archive data prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
| T1657 Financial Theft |
GroupAkira | Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom. |
| T1685 Disable or Modify Tools |
GroupAkira | Akira has disabled or modified security tools for defense evasion. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.