ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1041×

27 examples

TechniqueUsed byProcedure example
T1027.004
Compile After Delivery
GroupSea Turtle

Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments.

T1059.004
Unix Shell
GroupSea Turtle

Sea Turtle used shell scripts for post-exploitation execution in victim environments.

T1071.001
Web Protocols
GroupSea Turtle

Sea Turtle connected over TCP using HTTP to establish command and control channels.

T1074.002
Remote Data Staging
GroupSea Turtle

Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet.

T1078
Valid Accounts
GroupSea Turtle

Sea Turtle used compromised credentials to maintain long-term access to victim environments.

T1078.003
Local Accounts
GroupSea Turtle

Sea Turtle compromised cPanel accounts in victim environments.

T1114.001
Local Email Collection
GroupSea Turtle

Sea Turtle collected email archives from victim environments.

T1133
External Remote Services
GroupSea Turtle

Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations.

T1190
Exploit Public-Facing Application
GroupSea Turtle

Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns.

T1199
Trusted Relationship
GroupSea Turtle

Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers.

T1203
Exploitation for Client Execution
GroupSea Turtle

Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution.

T1213.006
Databases
GroupSea Turtle

Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines.

T1505.003
Web Shell
GroupSea Turtle

Sea Turtle deployed the SnappyTCP web shell during intrusion operations.

T1557
Adversary-in-the-Middle
GroupSea Turtle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.

T1560.001
Archive via Utility
GroupSea Turtle

Sea Turtle used the tar utility to create a local archive of email data on a victim system.

T1564.011
Ignore Process Interrupts
GroupSea Turtle

Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal.

T1566
Phishing
GroupSea Turtle

Sea Turtle used spear phishing to gain initial access to victims.

T1583
Acquire Infrastructure
GroupSea Turtle

Sea Turtle accessed victim networks from VPN service provider networks.

T1583.001
Domains
GroupSea Turtle

Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers.

T1583.002
DNS Server
GroupSea Turtle

Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.

T1583.003
Virtual Private Server
GroupSea Turtle

Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture.

T1584.002
DNS Server
GroupSea Turtle

Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups.

T1588.002
Tool
GroupSea Turtle

Sea Turtle has used tools such as Adminer during intrusions.

T1588.004
Digital Certificates
GroupSea Turtle

Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization.

T1608.003
Install Digital Certificate
GroupSea Turtle

Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations.

T1685.006
Clear Linux or Mac System Logs
GroupSea Turtle

Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.

T1690
Prevent Command History Logging
GroupSea Turtle

Sea Turtle unset the Bash and MySQL history files on victim systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.