Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT42 | APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1047 Windows Management Instrumentation |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1053.005 Scheduled Task |
GroupAPT42 | APT42 has used scheduled tasks for persistence. |
| T1056 Input Capture |
GroupAPT42 | APT42 has used credential harvesting websites. |
| T1056.001 Keylogging |
GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| T1059.001 PowerShell |
GroupAPT42 | APT42 has downloaded and executed PowerShell payloads. |
| T1059.005 Visual Basic |
GroupAPT42 | APT42 has used a VBScript to query anti-virus products. |
| T1070 Indicator Removal |
GroupAPT42 | APT42 has cleared Chrome browser history. |
| T1070.008 Clear Mailbox Data |
GroupAPT42 | APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| T1071.001 Web Protocols |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1082 System Information Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information. |
| T1087.001 Local Account |
GroupAPT42 | APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| T1102 Web Service |
GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1111 Multi-Factor Authentication Interception |
GroupAPT42 | APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
| T1112 Modify Registry |
GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| T1113 Screen Capture |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
| T1132.001 Standard Encoding |
GroupAPT42 | APT42 has encoded C2 traffic with Base64. |
| T1518.001 Security Software Discovery |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1530 Data from Cloud Storage |
GroupAPT42 | APT42 has collected data from Microsoft 365 environments. |
| T1539 Steal Web Session Cookie |
GroupAPT42 | APT42 has used custom malware to steal login and cookie data from common browsers. |
| T1547 Boot or Logon Autostart Execution |
GroupAPT42 | APT42 has modified the Registry to maintain persistence. |
| T1555.003 Credentials from Web Browsers |
GroupAPT42 | APT42 has used custom malware to steal credentials. |
| T1566.002 Spearphishing Link |
GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| T1573.002 Asymmetric Cryptography |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1583.001 Domains |
GroupAPT42 | APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations. |
| T1583.003 Virtual Private Server |
GroupAPT42 | APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment. |
| T1585.002 Email Accounts |
GroupAPT42 | APT42 has created email accounts to use in spearphishing operations. |
| T1588.002 Tool |
GroupAPT42 | APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection. |
| T1608.001 Upload Malware |
GroupAPT42 | APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application. |
| T1682 Query Public AI Services |
GroupAPT42 | APT42 has leveraged LLMs to search for official emails to build target lists, and conduct reconnaissance on potential business partners. |
| T1684.001 Impersonation |
GroupAPT42 | APT42 has impersonated legitimate people in phishing emails to gain credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.