Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1012 Query Registry |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| T1036.003 Rename Legitimate Utilities |
GroupDaggerfly | Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| T1053.005 Scheduled Task |
GroupDaggerfly | Daggerfly has attempted to use scheduled tasks for persistence in victim environments. |
| T1059.001 PowerShell |
GroupDaggerfly | Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1071.001 Web Protocols |
GroupDaggerfly | Daggerfly uses HTTP for command and control communication. |
| T1082 System Information Discovery |
GroupDaggerfly | Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication. |
| T1105 Ingress Tool Transfer |
GroupDaggerfly | Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines. |
| T1136.001 Local Account |
GroupDaggerfly | Daggerfly created a local account on victim machines to maintain access. |
| T1189 Drive-by Compromise |
GroupDaggerfly | Daggerfly has used strategic website compromise for initial access against victims. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1204.001 Malicious Link |
GroupDaggerfly | Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction. |
| T1218.011 Rundll32 |
GroupDaggerfly | Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary. |
| T1553.002 Code Signing |
GroupDaggerfly | Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| T1574.001 DLL |
GroupDaggerfly | Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
| T1584.004 Server |
GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
| T1587.002 Code Signing Certificates |
GroupDaggerfly | Daggerfly created code signing certificates to sign malicious macOS files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.