ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1033×

20 examples

TechniqueUsed byProcedure example
T1059.007
JavaScript
GroupStar Blizzard

Star Blizzard has used JavaScript to redirect victim traffic from an adversary controlled server to a server hosting the Evilginx phishing framework.

T1078
Valid Accounts
GroupStar Blizzard

Star Blizzard has used stolen credentials to sign into victim email accounts.

T1114.002
Remote Email Collection
GroupStar Blizzard

Star Blizzard has remotely accessed victims' email accounts to steal messages and attachments.

T1114.003
Email Forwarding Rule
GroupStar Blizzard

Star Blizzard has abused email forwarding rules to monitor the activities of a victim, steal information, and maintain persistent access after compromised credentials are reset.

T1204.002
Malicious File
GroupStar Blizzard

Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.

T1539
Steal Web Session Cookie
GroupStar Blizzard

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to
phishing domains.

T1550.004
Web Session Cookie
GroupStar Blizzard

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.

T1566.001
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails with malicious .pdf files to spread malware.

T1583
Acquire Infrastructure
GroupStar Blizzard

Star Blizzard has used HubSpot and MailerLite marketing platform services to hide the true sender of phishing emails.

T1583.001
Domains
GroupStar Blizzard

Star Blizzard has registered domains using randomized words and with names resembling legitimate organizations.

T1585.001
Social Media Accounts
GroupStar Blizzard

Star Blizzard has established fraudulent profiles on professional networking sites to conduct reconnaissance.

T1585.002
Email Accounts
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

T1586.002
Email Accounts
GroupStar Blizzard

Star Blizzard has used compromised email accounts to conduct spearphishing against
contacts of the original victim.

T1588.002
Tool
GroupStar Blizzard

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.

T1589
Gather Victim Identity Information
GroupStar Blizzard

Star Blizzard has identified ways to engage targets by researching potential victims' interests and social or professional contacts.

T1593
Search Open Websites/Domains
GroupStar Blizzard

Star Blizzard has used open-source research to identify information about victims to use in targeting.

T1598.002
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.

T1608.001
Upload Malware
GroupStar Blizzard

Star Blizzard has uploaded malicious payloads to cloud storage sites.

T1684.001
Impersonation
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.