ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1036×

30 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMoonstone Sleet

Moonstone Sleet retrieved credentials from LSASS memory.

T1016
System Network Configuration Discovery
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim network configuration.

T1027
Obfuscated Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation.

T1027.009
Embedded Payloads
GroupMoonstone Sleet

Moonstone Sleet embedded payloads in trojanized software for follow-on execution.

T1027.013
Encrypted/Encoded File
GroupMoonstone Sleet

Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion.

T1033
System Owner/User Discovery
GroupMoonstone Sleet

Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions.

T1053.005
Scheduled Task
GroupMoonstone Sleet

Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines.

T1071.001
Web Protocols
GroupMoonstone Sleet

Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads.

T1082
System Information Discovery
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim systems.

T1105
Ingress Tool Transfer
GroupMoonstone Sleet

Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.

T1140
Deobfuscate/Decode Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis.

T1195.002
Compromise Software Supply Chain
GroupMoonstone Sleet

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

T1204.002
Malicious File
GroupMoonstone Sleet

Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution.

T1217
Browser Information Discovery
GroupMoonstone Sleet

Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information.

T1486
Data Encrypted for Impact
GroupMoonstone Sleet

Moonstone Sleet has deployed ransomware in victim environments.

T1547.001
Registry Run Keys / Startup Folder
GroupMoonstone Sleet

Moonstone Sleet used registry run keys for process execution during initial victim infection.

T1566.001
Spearphishing Attachment
GroupMoonstone Sleet

Moonstone Sleet delivered various payloads to victims as spearphishing attachments.

T1566.003
Spearphishing via Service
GroupMoonstone Sleet

Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software.

T1569.002
Service Execution
GroupMoonstone Sleet

Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services.

T1583.001
Domains
GroupMoonstone Sleet

Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity.

T1583.003
Virtual Private Server
GroupMoonstone Sleet

Moonstone Sleet registered virtual private servers to host payloads for download.

T1585.001
Social Media Accounts
GroupMoonstone Sleet

Moonstone Sleet has created social media accounts to interact with victims.

T1585.002
Email Accounts
GroupMoonstone Sleet

Moonstone Sleet has created email accounts to interact with victims, including for phishing purposes.

T1587
Develop Capabilities
GroupMoonstone Sleet

Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims.

T1587.001
Malware
GroupMoonstone Sleet

Moonstone Sleet has developed custom malware, including a malware delivery mechanism masquerading as a legitimate game.

T1589.002
Email Addresses
GroupMoonstone Sleet

Moonstone Sleet gathered victim email address information for follow-on phishing activity.

T1591
Gather Victim Org Information
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim organizations through email and social media interaction.

T1598
Phishing for Information
GroupMoonstone Sleet

Moonstone Sleet has interacted with victims to gather information via email.

T1598.003
Spearphishing Link
GroupMoonstone Sleet

Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages.

T1608.001
Upload Malware
GroupMoonstone Sleet

Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.