Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMoonstone Sleet | Moonstone Sleet retrieved credentials from LSASS memory. |
| T1016 System Network Configuration Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim network configuration. |
| T1027 Obfuscated Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
| T1027.009 Embedded Payloads |
GroupMoonstone Sleet | Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| T1027.013 Encrypted/Encoded File |
GroupMoonstone Sleet | Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion. |
| T1033 System Owner/User Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions. |
| T1053.005 Scheduled Task |
GroupMoonstone Sleet | Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines. |
| T1071.001 Web Protocols |
GroupMoonstone Sleet | Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1082 System Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim systems. |
| T1105 Ingress Tool Transfer |
GroupMoonstone Sleet | Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis. |
| T1195.002 Compromise Software Supply Chain |
GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1204.002 Malicious File |
GroupMoonstone Sleet | Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1217 Browser Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| T1486 Data Encrypted for Impact |
GroupMoonstone Sleet | Moonstone Sleet has deployed ransomware in victim environments. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMoonstone Sleet | Moonstone Sleet used registry run keys for process execution during initial victim infection. |
| T1566.001 Spearphishing Attachment |
GroupMoonstone Sleet | Moonstone Sleet delivered various payloads to victims as spearphishing attachments. |
| T1566.003 Spearphishing via Service |
GroupMoonstone Sleet | Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software. |
| T1569.002 Service Execution |
GroupMoonstone Sleet | Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services. |
| T1583.001 Domains |
GroupMoonstone Sleet | Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity. |
| T1583.003 Virtual Private Server |
GroupMoonstone Sleet | Moonstone Sleet registered virtual private servers to host payloads for download. |
| T1585.001 Social Media Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created social media accounts to interact with victims. |
| T1585.002 Email Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created email accounts to interact with victims, including for phishing purposes. |
| T1587 Develop Capabilities |
GroupMoonstone Sleet | Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims. |
| T1587.001 Malware |
GroupMoonstone Sleet | Moonstone Sleet has developed custom malware, including a malware delivery mechanism masquerading as a legitimate game. |
| T1589.002 Email Addresses |
GroupMoonstone Sleet | Moonstone Sleet gathered victim email address information for follow-on phishing activity. |
| T1591 Gather Victim Org Information |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim organizations through email and social media interaction. |
| T1598 Phishing for Information |
GroupMoonstone Sleet | Moonstone Sleet has interacted with victims to gather information via email. |
| T1598.003 Spearphishing Link |
GroupMoonstone Sleet | Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages. |
| T1608.001 Upload Malware |
GroupMoonstone Sleet | Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.