ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1044×

32 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT42

APT42 has masqueraded the VINETHORN payload as a VPN application.

T1047
Windows Management Instrumentation
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1053.005
Scheduled Task
GroupAPT42

APT42 has used scheduled tasks for persistence.

T1056
Input Capture
GroupAPT42

APT42 has used credential harvesting websites.

T1056.001
Keylogging
GroupAPT42

APT42 has used custom malware to log keystrokes.

T1059.001
PowerShell
GroupAPT42

APT42 has downloaded and executed PowerShell payloads.

T1059.005
Visual Basic
GroupAPT42

APT42 has used a VBScript to query anti-virus products.

T1070
Indicator Removal
GroupAPT42

APT42 has cleared Chrome browser history.

T1070.008
Clear Mailbox Data
GroupAPT42

APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks.

T1071.001
Web Protocols
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1082
System Information Discovery
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information.

T1087.001
Local Account
GroupAPT42

APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.

T1102
Web Service
GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1111
Multi-Factor Authentication Interception
GroupAPT42

APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens.

T1112
Modify Registry
GroupAPT42

APT42 has modified Registry keys to maintain persistence.

T1113
Screen Capture
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots.

T1132.001
Standard Encoding
GroupAPT42

APT42 has encoded C2 traffic with Base64.

T1518.001
Security Software Discovery
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1530
Data from Cloud Storage
GroupAPT42

APT42 has collected data from Microsoft 365 environments.

T1539
Steal Web Session Cookie
GroupAPT42

APT42 has used custom malware to steal login and cookie data from common browsers.

T1547
Boot or Logon Autostart Execution
GroupAPT42

APT42 has modified the Registry to maintain persistence.

T1555.003
Credentials from Web Browsers
GroupAPT42

APT42 has used custom malware to steal credentials.

T1566.002
Spearphishing Link
GroupAPT42

APT42 has sent spearphishing emails containing malicious links.

T1573.002
Asymmetric Cryptography
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1583.001
Domains
GroupAPT42

APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations.

T1583.003
Virtual Private Server
GroupAPT42

APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.

T1585.002
Email Accounts
GroupAPT42

APT42 has created email accounts to use in spearphishing operations.

T1588.002
Tool
GroupAPT42

APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection.

T1608.001
Upload Malware
GroupAPT42

APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application.

T1682
Query Public AI Services
GroupAPT42

APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners.

T1684.001
Impersonation
GroupAPT42

APT42 has impersonated legitimate people in phishing emails to gain credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.