Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
GroupStorm-1811 | Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket. |
| T1021.004 SSH |
GroupStorm-1811 | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1027.013 Encrypted/Encoded File |
GroupStorm-1811 | Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process. |
| T1033 System Owner/User Discovery |
GroupStorm-1811 | Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator. |
| T1036 Masquerading |
GroupStorm-1811 | Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupStorm-1811 | Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package. |
| T1036.010 Masquerade Account Name |
GroupStorm-1811 | Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupStorm-1811 | Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP). |
| T1056 Input Capture |
GroupStorm-1811 | Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item. |
| T1059.001 PowerShell |
GroupStorm-1811 | Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server. |
| T1059.003 Windows Command Shell |
GroupStorm-1811 | Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines. |
| T1074.001 Local Data Staging |
GroupStorm-1811 | Storm-1811 has locally staged captured credentials for subsequent manual exfiltration. |
| T1087.002 Domain Account |
GroupStorm-1811 | Storm-1811 has performed domain account enumeration during intrusions. |
| T1105 Ingress Tool Transfer |
GroupStorm-1811 | Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices. |
| T1140 Deobfuscate/Decode Files or Information |
GroupStorm-1811 | Storm-1811 has distributed password-protected archives such as ZIP files during intrusions. |
| T1204.002 Malicious File |
GroupStorm-1811 | Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity. |
| T1219.002 Remote Desktop Software |
GroupStorm-1811 | Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk. |
| T1222.001 Windows Permissions |
GroupStorm-1811 | Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments. |
| T1482 Domain Trust Discovery |
GroupStorm-1811 | Storm-1811 has enumerated domain accounts and access during intrusions. |
| T1486 Data Encrypted for Impact |
GroupStorm-1811 | Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupStorm-1811 | Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices. |
| T1566.002 Spearphishing Link |
GroupStorm-1811 | Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials. |
| T1566.003 Spearphishing via Service |
GroupStorm-1811 | Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel. |
| T1566.004 Spearphishing Voice |
GroupStorm-1811 | Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access. |
| T1570 Lateral Tool Transfer |
GroupStorm-1811 | Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks. |
| T1574.001 DLL |
GroupStorm-1811 | Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload. |
| T1583.001 Domains |
GroupStorm-1811 | Storm-1811 has created domains for use with RMM tools. |
| T1585.003 Cloud Accounts |
GroupStorm-1811 | Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes. |
| T1588.002 Tool |
GroupStorm-1811 | Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations. |
| T1667 Email Bombing |
GroupStorm-1811 | Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem. |
| T1684.001 Impersonation |
GroupStorm-1811 | Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.