Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1033 System Owner/User Discovery |
GroupWinter Vivern | Winter Vivern PowerShell scripts execute `whoami` to identify the executing user. |
| T1036 Masquerading |
GroupWinter Vivern | Winter Vivern created specially-crafted documents mimicking legitimate government or similar documents during phishing campaigns. |
| T1036.004 Masquerade Task or Service |
GroupWinter Vivern | Winter Vivern has distributed malicious scripts and executables mimicking virus scanners. |
| T1041 Exfiltration Over C2 Channel |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1053.005 Scheduled Task |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts that would subsequently attempt to establish persistence by creating scheduled tasks objects to periodically retrieve and execute remotely-hosted payloads. |
| T1056.003 Web Portal Capture |
GroupWinter Vivern | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| T1059 Command and Scripting Interpreter |
GroupWinter Vivern | Winter Vivern used XLM 4.0 macros for initial code execution for malicious document files. |
| T1059.001 PowerShell |
GroupWinter Vivern | Winter Vivern passed execution from document macros to PowerShell scripts during initial access operations. Winter Vivern used batch scripts that called PowerShell commands as part of initial access and installation operations. |
| T1059.003 Windows Command Shell |
GroupWinter Vivern | Winter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools. |
| T1059.007 JavaScript |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript to exploit targets when exploiting Roundcube Webmail servers. |
| T1071.001 Web Protocols |
GroupWinter Vivern | Winter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity. |
| T1082 System Information Discovery |
GroupWinter Vivern | Winter Vivern script execution includes basic victim information gathering steps which are then transmitted to command and control servers. |
| T1083 File and Directory Discovery |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers. |
| T1105 Ingress Tool Transfer |
GroupWinter Vivern | Winter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads. |
| T1113 Screen Capture |
GroupWinter Vivern | Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines. |
| T1114.001 Local Email Collection |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of exfiltrating email messages from exploited email servers. |
| T1119 Automated Collection |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWinter Vivern | Winter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages. |
| T1189 Drive-by Compromise |
GroupWinter Vivern | Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software. |
| T1190 Exploit Public-Facing Application |
GroupWinter Vivern | Winter Vivern has exploited known and zero-day vulnerabilities in software usch as Roundcube Webmail servers and the "Follina" vulnerability. |
| T1204.001 Malicious Link |
GroupWinter Vivern | Winter Vivern has mimicked legitimate government-related domains to deliver malicious webpages containing links to documents or other content for user execution. |
| T1566.001 Spearphishing Attachment |
GroupWinter Vivern | Winter Vivern leverages malicious attachments delivered via email for initial access activity. |
| T1583.001 Domains |
GroupWinter Vivern | Winter Vivern registered domains mimicking other entities throughout various campaigns. |
| T1583.003 Virtual Private Server |
GroupWinter Vivern | Winter Vivern used adversary-owned and -controlled servers to host web vulnerability scanning applications. |
| T1584.006 Web Services |
GroupWinter Vivern | Winter Vivern has used compromised WordPress sites to host malicious payloads for download. |
| T1595.002 Vulnerability Scanning |
GroupWinter Vivern | Winter Vivern has used remotely-hosted instances of the Acunetix vulnerability scanner. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.