Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
GroupVelvet Ant | Velvet Ant has transferred tools within victim environments using SMB. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVelvet Ant | Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows. |
| T1037.004 RC Scripts |
GroupVelvet Ant | Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence. |
| T1040 Network Sniffing |
GroupVelvet Ant | Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices. |
| T1047 Windows Management Instrumentation |
GroupVelvet Ant | Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI. |
| T1049 System Network Connections Discovery |
GroupVelvet Ant | Velvet Ant has enumerated existing network connections on victim devices. |
| T1055 Process Injection |
GroupVelvet Ant | Velvet Ant initial execution included launching multiple `svchost` processes and injecting code into them. |
| T1059.004 Unix Shell |
GroupVelvet Ant | Velvet Ant used a custom tool, VELVETSTING, to parse encoded inbound commands to compromised F5 BIG-IP devices and then execute them via the Unix shell. |
| T1071 Application Layer Protocol |
GroupVelvet Ant | Velvet Ant has used reverse SSH tunnels to communicate to victim devices. |
| T1078.003 Local Accounts |
GroupVelvet Ant | Velvet Ant accessed vulnerable Cisco switch devices using accounts with administrator privileges. |
| T1083 File and Directory Discovery |
GroupVelvet Ant | Velvet Ant has enumerated local files and folders on victim devices. |
| T1090.001 Internal Proxy |
GroupVelvet Ant | Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| T1132 Data Encoding |
GroupVelvet Ant | Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution. |
| T1133 External Remote Services |
GroupVelvet Ant | Velvet Ant has leveraged access to internet-facing remote services to compromise and retain access to victim environments. |
| T1211 Exploitation for Stealth |
GroupVelvet Ant | Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution. |
| T1569.002 Service Execution |
GroupVelvet Ant | Velvet Ant executed and installed PlugX as a Windows service. |
| T1570 Lateral Tool Transfer |
GroupVelvet Ant | Velvet Ant transferred files laterally within victim networks through the Impacket toolkit. |
| T1571 Non-Standard Port |
GroupVelvet Ant | Velvet Ant has used random high number ports for PlugX listeners on victim devices. |
| T1573.002 Asymmetric Cryptography |
GroupVelvet Ant | Velvet Ant has used a reverse SSH shell to securely communicate with victim devices. |
| T1574.001 DLL |
GroupVelvet Ant | Velvet Ant has used malicious DLLs executed via legitimate EXE files through DLL search order hijacking to launch follow-on payloads such as PlugX. |
| T1685 Disable or Modify Tools |
GroupVelvet Ant | Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations. |
| T1686 Disable or Modify System Firewall |
GroupVelvet Ant | Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.