Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAgrius | Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| T1003.002 Security Account Manager |
GroupAgrius | Agrius dumped the SAM file on victim machines to capture credentials. |
| T1005 Data from Local System |
GroupAgrius | Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| T1018 Remote System Discovery |
GroupAgrius | Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| T1021.001 Remote Desktop Protocol |
GroupAgrius | Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments. |
| T1036 Masquerading |
GroupAgrius | Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| T1041 Exfiltration Over C2 Channel |
GroupAgrius | Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. |
| T1046 Network Service Discovery |
GroupAgrius | Agrius used the open-source port scanner |
| T1059.003 Windows Command Shell |
GroupAgrius | Agrius uses ASPXSpy web shells to enable follow-on command execution via |
| T1074.001 Local Data Staging |
GroupAgrius | Agrius has used the folder, |
| T1078.002 Domain Accounts |
GroupAgrius | Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1110 Brute Force |
GroupAgrius | Agrius engaged in various brute forcing activities via SMB in victim environments. |
| T1110.003 Password Spraying |
GroupAgrius | Agrius engaged in password spraying via SMB in victim environments. |
| T1119 Automated Collection |
GroupAgrius | Agrius used a custom tool, |
| T1140 Deobfuscate/Decode Files or Information |
GroupAgrius | Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
| T1190 Exploit Public-Facing Application |
GroupAgrius | Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity. |
| T1505.003 Web Shell |
GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| T1543.003 Windows Service |
GroupAgrius | Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence. |
| T1560.001 Archive via Utility |
GroupAgrius | Agrius used 7zip to archive extracted data in preparation for exfiltration. |
| T1570 Lateral Tool Transfer |
GroupAgrius | Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as |
| T1583 Acquire Infrastructure |
GroupAgrius | Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN. |
| T1685 Disable or Modify Tools |
GroupAgrius | Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.