ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1034×

17 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction.

T1012
Query Registry
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines.

T1036.003
Rename Legitimate Utilities
GroupDaggerfly

Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution.

T1053.005
Scheduled Task
GroupDaggerfly

Daggerfly has attempted to use scheduled tasks for persistence in victim environments.

T1059.001
PowerShell
GroupDaggerfly

Daggerfly used PowerShell to download and execute remote-hosted files on victim systems.

T1071.001
Web Protocols
GroupDaggerfly

Daggerfly uses HTTP for command and control communication.

T1082
System Information Discovery
GroupDaggerfly

Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication.

T1105
Ingress Tool Transfer
GroupDaggerfly

Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines.

T1136.001
Local Account
GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

T1189
Drive-by Compromise
GroupDaggerfly

Daggerfly has used strategic website compromise for initial access against victims.

T1195.002
Compromise Software Supply Chain
GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

T1204.001
Malicious Link
GroupDaggerfly

Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction.

T1218.011
Rundll32
GroupDaggerfly

Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary.

T1553.002
Code Signing
GroupDaggerfly

Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments.

T1574.001
DLL
GroupDaggerfly

Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity.

T1584.004
Server
GroupDaggerfly

Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion.

T1587.002
Code Signing Certificates
GroupDaggerfly

Daggerfly created code signing certificates to sign malicious macOS files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.