ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1047×

22 examples

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupVelvet Ant

Velvet Ant has transferred tools within victim environments using SMB.

T1036.005
Match Legitimate Resource Name or Location
GroupVelvet Ant

Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows.

T1037.004
RC Scripts
GroupVelvet Ant

Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence.

T1040
Network Sniffing
GroupVelvet Ant

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

T1047
Windows Management Instrumentation
GroupVelvet Ant

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1049
System Network Connections Discovery
GroupVelvet Ant

Velvet Ant has enumerated existing network connections on victim devices.

T1055
Process Injection
GroupVelvet Ant

Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them.

T1059.004
Unix Shell
GroupVelvet Ant

Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell.

T1071
Application Layer Protocol
GroupVelvet Ant

Velvet Ant has used reverse SSH tunnels to communicate to victim devices.

T1078.003
Local Accounts
GroupVelvet Ant

Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges.

T1083
File and Directory Discovery
GroupVelvet Ant

Velvet Ant has enumerated local files and folders on victim devices.

T1090.001
Internal Proxy
GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1132
Data Encoding
GroupVelvet Ant

Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution.

T1133
External Remote Services
GroupVelvet Ant

Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments.

T1211
Exploitation for Stealth
GroupVelvet Ant

Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution.

T1569.002
Service Execution
GroupVelvet Ant

Velvet Ant executed and installed PlugX as a Windows service.

T1570
Lateral Tool Transfer
GroupVelvet Ant

Velvet Ant transferred files laterally within victim networks through the Impacket toolkit.

T1571
Non-Standard Port
GroupVelvet Ant

Velvet Ant has used random high number ports for PlugX listeners on victim devices.

T1573.002
Asymmetric Cryptography
GroupVelvet Ant

Velvet Ant has used a reverse SSH shell to securely communicate with victim devices.

T1574.001
DLL
GroupVelvet Ant

Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX.

T1685
Disable or Modify Tools
GroupVelvet Ant

Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations.

T1686
Disable or Modify System Firewall
GroupVelvet Ant

Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.