Real-world descriptions of how a group, tool or campaign used a technique.
49 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupUNC3886 | UNC3886 has used MiniDump to dump process memory and search for cleartext credentials. |
| T1008 Fallback Channels |
GroupUNC3886 | UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| T1014 Rootkit |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1027.005 Indicator Removal from Tools |
GroupUNC3886 | UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release. |
| T1036.004 Masquerade Task or Service |
GroupUNC3886 | UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1037 Boot or Logon Initialization Scripts |
GroupUNC3886 | UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| T1037.004 RC Scripts |
GroupUNC3886 | UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence. |
| T1040 Network Sniffing |
GroupUNC3886 | UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets. |
| T1057 Process Discovery |
GroupUNC3886 | UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
| T1059.001 PowerShell |
GroupUNC3886 | UNC3886 has used a PowerShell script to search memory dumps for credentials. |
| T1059.003 Windows Command Shell |
GroupUNC3886 | UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`. |
| T1059.004 Unix Shell |
GroupUNC3886 | UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.006 Python |
GroupUNC3886 | UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.012 Hypervisor CLI |
GroupUNC3886 | UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
| T1068 Exploitation for Privilege Escalation |
GroupUNC3886 | UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs. |
| T1070.004 File Deletion |
GroupUNC3886 | UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk. |
| T1070.006 Timestomp |
GroupUNC3886 | UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs). |
| T1070.007 Clear Network Connection History and Configurations |
GroupUNC3886 | UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources. |
| T1074.001 Local Data Staging |
GroupUNC3886 | UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`. |
| T1078 Valid Accounts |
GroupUNC3886 | UNC3886 has used tools to hijack valid SSH accounts. |
| T1078.001 Default Accounts |
GroupUNC3886 | UNC3886 has harvested and used vCenter Server service accounts. |
| T1083 File and Directory Discovery |
GroupUNC3886 | UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines. |
| T1095 Non-Application Layer Protocol |
GroupUNC3886 | UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts. |
| T1124 System Time Discovery |
GroupUNC3886 | UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts. |
| T1190 Exploit Public-Facing Application |
GroupUNC3886 | UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access. |
| T1203 Exploitation for Client Execution |
GroupUNC3886 | UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs. |
| T1205 Traffic Signaling |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices. |
| T1205.001 Port Knocking |
GroupUNC3886 | UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking. |
| T1212 Exploitation for Credential Access |
GroupUNC3886 | UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB. |
| T1218.011 Rundll32 |
GroupUNC3886 | UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1548 Abuse Elevation Control Mechanism |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation. |
| T1554 Compromise Host Software Binary |
GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| T1555.005 Password Managers |
GroupUNC3886 | UNC3886 has targeted KeyPass password database files for credential access. |
| T1560.001 Archive via Utility |
GroupUNC3886 | UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems. |
| T1560.003 Archive via Custom Method |
GroupUNC3886 | UNC3886 has XOR encrypted and Gzip compressed captured credentials. |
| T1564.011 Ignore Process Interrupts |
GroupUNC3886 | UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted. |
| T1570 Lateral Tool Transfer |
GroupUNC3886 | UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs. |
| T1587.001 Malware |
GroupUNC3886 | UNC3886 has deployed custom malware families on Fortinet and VMware systems. |
| T1587.004 Exploits |
GroupUNC3886 | UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter. |
| T1588.001 Malware |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA. |
| T1588.004 Digital Certificates |
GroupUNC3886 | UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device. |
| T1673 Virtual Machine Discovery |
GroupUNC3886 | UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs. |
| T1675 ESXi Administration Command |
GroupUNC3886 | UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host. |
| T1681 Search Threat Vendor Data |
GroupUNC3886 | UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release. |
| T1685 Disable or Modify Tools |
GroupUNC3886 | UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1690 Prevent Command History Logging |
GroupUNC3886 | UNC3886 has tampered with and disabled logging services on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.