Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupSaint Bear | Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.013 Encrypted/Encoded File |
GroupSaint Bear | Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader. |
| T1059 Command and Scripting Interpreter |
GroupSaint Bear | Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059.001 PowerShell |
GroupSaint Bear | Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads. |
| T1059.003 Windows Command Shell |
GroupSaint Bear | Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality. |
| T1059.007 JavaScript |
GroupSaint Bear | Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1112 Modify Registry |
GroupSaint Bear | Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
| T1203 Exploitation for Client Execution |
GroupSaint Bear | Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments. |
| T1204.001 Malicious Link |
GroupSaint Bear | Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1204.002 Malicious File |
GroupSaint Bear | Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems. |
| T1497 Virtualization/Sandbox Evasion |
GroupSaint Bear | Saint Bear contains several anti-analysis and anti-virtualization checks. |
| T1553.002 Code Signing |
GroupSaint Bear | Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1566.001 Spearphishing Attachment |
GroupSaint Bear | Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access. |
| T1583.006 Web Services |
GroupSaint Bear | Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations. |
| T1589.002 Email Addresses |
GroupSaint Bear | Saint Bear gathered victim email information in advance of phishing operations for targeted attacks. |
| T1608.001 Upload Malware |
GroupSaint Bear | Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails. |
| T1684.001 Impersonation |
GroupSaint Bear | Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources. |
| T1685 Disable or Modify Tools |
GroupSaint Bear | Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.