ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1046×

31 examples

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupStorm-1811

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.

T1021.004
SSH
GroupStorm-1811

Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.

T1027.013
Encrypted/Encoded File
GroupStorm-1811

Storm-1811 XOR encodes a Cobalt Strike installation payload in a DLL file that is decoded with a hardcoded key when called by a legitimate 7zip installation process.

T1033
System Owner/User Discovery
GroupStorm-1811

Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator.

T1036
Masquerading
GroupStorm-1811

Storm-1811 has prompted users to download and execute batch scripts that masquerade as legitimate update files during initial access and social engineering operations.

T1036.005
Match Legitimate Resource Name or Location
GroupStorm-1811

Storm-1811 has disguised Cobalt Strike installers as a malicious DLL masquerading as part of a legitimate 7zip installation package.

T1036.010
Masquerade Account Name
GroupStorm-1811

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupStorm-1811

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).

T1056
Input Capture
GroupStorm-1811

Storm-1811 has used a PowerShell script to capture user credentials after prompting a user to authenticate to run a malicious script masquerading as a legitimate update item.

T1059.001
PowerShell
GroupStorm-1811

Storm-1811 has used PowerShell for multiple purposes, such as using PowerShell scripts executing in an infinite loop to create an SSH connection to a command and control server.

T1059.003
Windows Command Shell
GroupStorm-1811

Storm-1811 has used multiple batch scripts during initial access and subsequent actions on victim machines.

T1074.001
Local Data Staging
GroupStorm-1811

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1087.002
Domain Account
GroupStorm-1811

Storm-1811 has performed domain account enumeration during intrusions.

T1105
Ingress Tool Transfer
GroupStorm-1811

Storm-1811 has used scripted `cURL` commands, BITSAdmin, and other mechanisms to retrieve follow-on batch scripts and tools for execution on victim devices.

T1140
Deobfuscate/Decode Files or Information
GroupStorm-1811

Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.

T1204.002
Malicious File
GroupStorm-1811

Storm-1811 has prompted users to execute downloaded software and payloads as the result of social engineering activity.

T1219.002
Remote Desktop Software
GroupStorm-1811

Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.

T1222.001
Windows Permissions
GroupStorm-1811

Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.

T1482
Domain Trust Discovery
GroupStorm-1811

Storm-1811 has enumerated domain accounts and access during intrusions.

T1486
Data Encrypted for Impact
GroupStorm-1811

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.

T1547.001
Registry Run Keys / Startup Folder
GroupStorm-1811

Storm-1811 has created Windows Registry Run keys that execute various batch scripts to establish persistence on victim devices.

T1566.002
Spearphishing Link
GroupStorm-1811

Storm-1811 has distributed malicious links to victims that redirect to EvilProxy-based phishing sites to harvest credentials.

T1566.003
Spearphishing via Service
GroupStorm-1811

Storm-1811 has used Microsoft Teams to send messages and initiate voice calls to victims posing as IT support personnel.

T1566.004
Spearphishing Voice
GroupStorm-1811

Storm-1811 has initiated voice calls with victims posing as IT support to prompt users to download and execute scripts and other tools for initial access.

T1570
Lateral Tool Transfer
GroupStorm-1811

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.

T1574.001
DLL
GroupStorm-1811

Storm-1811 has deployed a malicious DLL (7z.DLL) that is sideloaded by a modified, legitimate installer (7zG.exe) when that installer is executed with an additional command line parameter of `b` at runtime to load a Cobalt Strike beacon payload.

T1583.001
Domains
GroupStorm-1811

Storm-1811 has created domains for use with RMM tools.

T1585.003
Cloud Accounts
GroupStorm-1811

Storm-1811 has created malicious accounts to enable activity via Microsoft Teams, typically spoofing various IT support and helpdesk themes.

T1588.002
Tool
GroupStorm-1811

Storm-1811 acquired various legitimate and malicious tools, such as RMM software and commodity malware packages, for operations.

T1667
Email Bombing
GroupStorm-1811

Storm-1811 has deployed large volumes of non-malicious email spam to victims in order to prompt follow-on interactions with the threat actor posing as IT support or helpdesk to resolve the problem.

T1684.001
Impersonation
GroupStorm-1811

Storm-1811 impersonates help desk and IT support personnel for phishing and social engineering purposes during initial access to victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.