ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1031×

18 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupSaint Bear

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.013
Encrypted/Encoded File
GroupSaint Bear

Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.

T1059
Command and Scripting Interpreter
GroupSaint Bear

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059.001
PowerShell
GroupSaint Bear

Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads.

T1059.003
Windows Command Shell
GroupSaint Bear

Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality.

T1059.007
JavaScript
GroupSaint Bear

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1112
Modify Registry
GroupSaint Bear

Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality.

T1203
Exploitation for Client Execution
GroupSaint Bear

Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments.

T1204.001
Malicious Link
GroupSaint Bear

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1204.002
Malicious File
GroupSaint Bear

Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems.

T1497
Virtualization/Sandbox Evasion
GroupSaint Bear

Saint Bear contains several anti-analysis and anti-virtualization checks.

T1553.002
Code Signing
GroupSaint Bear

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1566.001
Spearphishing Attachment
GroupSaint Bear

Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access.

T1583.006
Web Services
GroupSaint Bear

Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations.

T1589.002
Email Addresses
GroupSaint Bear

Saint Bear gathered victim email information in advance of phishing operations for targeted attacks.

T1608.001
Upload Malware
GroupSaint Bear

Saint Bear has used the Discord content delivery network for hosting malicious content referenced in links and emails.

T1684.001
Impersonation
GroupSaint Bear

Saint Bear has impersonated government and related entities in both phishing activity and developing web sites with malicious links that mimic legitimate resources.

T1685
Disable or Modify Tools
GroupSaint Bear

Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.