Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.004 Compile After Delivery |
GroupSea Turtle | Sea Turtle downloaded source code files from remote addresses then compiled them locally via GCC in victim environments. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1071.001 Web Protocols |
GroupSea Turtle | Sea Turtle connected over TCP using HTTP to establish command and control channels. |
| T1074.002 Remote Data Staging |
GroupSea Turtle | Sea Turtle staged collected email archives in the public web directory of a website that was accessible from the internet. |
| T1078 Valid Accounts |
GroupSea Turtle | Sea Turtle used compromised credentials to maintain long-term access to victim environments. |
| T1078.003 Local Accounts |
GroupSea Turtle | Sea Turtle compromised cPanel accounts in victim environments. |
| T1114.001 Local Email Collection |
GroupSea Turtle | Sea Turtle collected email archives from victim environments. |
| T1133 External Remote Services |
GroupSea Turtle | Sea Turtle has used external-facing SSH to achieve initial access to the IT environments of victim organizations. |
| T1190 Exploit Public-Facing Application |
GroupSea Turtle | Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns. |
| T1199 Trusted Relationship |
GroupSea Turtle | Sea Turtle targeted third-party entities in trusted relationships with primary targets to ultimately achieve access at primary targets. Entities targeted included DNS registrars, telecommunication companies, and internet service providers. |
| T1203 Exploitation for Client Execution |
GroupSea Turtle | Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution. |
| T1213.006 Databases |
GroupSea Turtle | Sea Turtle used the tool Adminer to remotely logon to the MySQL service of victim machines. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1557 Adversary-in-the-Middle |
GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1560.001 Archive via Utility |
GroupSea Turtle | Sea Turtle used the tar utility to create a local archive of email data on a victim system. |
| T1564.011 Ignore Process Interrupts |
GroupSea Turtle | Sea Turtle executed SnappyTCP using the tool NoHup, which keeps the malware running on a system after exiting the shell or terminal. |
| T1566 Phishing |
GroupSea Turtle | Sea Turtle used spear phishing to gain initial access to victims. |
| T1583 Acquire Infrastructure |
GroupSea Turtle | Sea Turtle accessed victim networks from VPN service provider networks. |
| T1583.001 Domains |
GroupSea Turtle | Sea Turtle registered domains for authoritative name servers used in DNS hijacking activity and for command and control servers. |
| T1583.002 DNS Server |
GroupSea Turtle | Sea Turtle built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials. |
| T1583.003 Virtual Private Server |
GroupSea Turtle | Sea Turtle created adversary-in-the-middle servers to impersonate legitimate services and enable credential capture. |
| T1584.002 DNS Server |
GroupSea Turtle | Sea Turtle modified Name Server (NS) items to refer to Sea Turtle-controlled DNS servers to provide responses for all DNS lookups. |
| T1588.002 Tool |
GroupSea Turtle | Sea Turtle has used tools such as Adminer during intrusions. |
| T1588.004 Digital Certificates |
GroupSea Turtle | Sea Turtle created new certificates using a technique called the actors performed "certificate impersonation," a technique in which Sea Turtle obtained a certificate authority-signed X.509 certificate from another provider for the same domain imitating the one already used by the targeted organization. |
| T1608.003 Install Digital Certificate |
GroupSea Turtle | Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSea Turtle | Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions. |
| T1690 Prevent Command History Logging |
GroupSea Turtle | Sea Turtle unset the Bash and MySQL history files on victim systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.