ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1048×

49 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupUNC3886

UNC3886 has used MiniDump to dump process memory and search for cleartext credentials.

T1008
Fallback Channels
GroupUNC3886

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

T1014
Rootkit
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs.

T1021.004
SSH
GroupUNC3886

UNC3886 has established remote SSH access to targeted ESXi hosts.

T1027.005
Indicator Removal from Tools
GroupUNC3886

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

T1036.004
Masquerade Task or Service
GroupUNC3886

UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall.

T1037
Boot or Logon Initialization Scripts
GroupUNC3886

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

T1037.004
RC Scripts
GroupUNC3886

UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence.

T1040
Network Sniffing
GroupUNC3886

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

T1057
Process Discovery
GroupUNC3886

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

T1059.001
PowerShell
GroupUNC3886

UNC3886 has used a PowerShell script to search memory dumps for credentials.

T1059.003
Windows Command Shell
GroupUNC3886

UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`.

T1059.004
Unix Shell
GroupUNC3886

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.006
Python
GroupUNC3886

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.012
Hypervisor CLI
GroupUNC3886

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

T1068
Exploitation for Privilege Escalation
GroupUNC3886

UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs.

T1070.004
File Deletion
GroupUNC3886

UNC3886 has used the the esxcli command line to remove files created by malicious vSphere Installation Bundles from disk.

T1070.006
Timestomp
GroupUNC3886

UNC3886 has used scripts to timestomp ESXi hosts prior to installing malicious vSphere Installation Bundles (VIBs).

T1070.007
Clear Network Connection History and Configurations
GroupUNC3886

UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources.

T1074.001
Local Data Staging
GroupUNC3886

UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`.

T1078
Valid Accounts
GroupUNC3886

UNC3886 has used tools to hijack valid SSH accounts.

T1078.001
Default Accounts
GroupUNC3886

UNC3886 has harvested and used vCenter Server service accounts.

T1083
File and Directory Discovery
GroupUNC3886

UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1124
System Time Discovery
GroupUNC3886

UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts.

T1190
Exploit Public-Facing Application
GroupUNC3886

UNC3886 has exploited CVE-2022-42475 in FortiOS SSL VPNs to obtain access.

T1203
Exploitation for Client Execution
GroupUNC3886

UNC3886 has exoloited CVE-2023-34048 to enable command execution on vCenter servers and CVE-2023-20867 in VMware Tools to execute unauthenticated Guest Operations from ESXi hosts to guest VMs.

T1205
Traffic Signaling
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility to listen for specialized command packets on compromised FortiManager devices.

T1205.001
Port Knocking
GroupUNC3886

UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking.

T1212
Exploitation for Credential Access
GroupUNC3886

UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB.

T1218.011
Rundll32
GroupUNC3886

UNC3886 has used rundll32.exe to execute MiniDump for dumping LSASS process memory.

T1505.006
vSphere Installation Bundles
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors.

T1548
Abuse Elevation Control Mechanism
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) that contained modified descriptor XML files with the `acceptance-level` set to `partner` which allowed for privilege escalation.

T1554
Compromise Host Software Binary
GroupUNC3886

UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality.

T1555.005
Password Managers
GroupUNC3886

UNC3886 has targeted KeyPass password database files for credential access.

T1560.001
Archive via Utility
GroupUNC3886

UNC3886 has used Gzip and the Windows command `makecab` to compress files and stolen credentials from victim systems.

T1560.003
Archive via Custom Method
GroupUNC3886

UNC3886 has XOR encrypted and Gzip compressed captured credentials.

T1564.011
Ignore Process Interrupts
GroupUNC3886

UNC3886 modified the startup file `/etc/init.d/localnet` to execute the line `nohup /bin/support &` so the script would run when the system was rebooted.

T1570
Lateral Tool Transfer
GroupUNC3886

UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs.

T1587.001
Malware
GroupUNC3886

UNC3886 has deployed custom malware families on Fortinet and VMware systems.

T1587.004
Exploits
GroupUNC3886

UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.

T1588.001
Malware
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA.

T1588.004
Digital Certificates
GroupUNC3886

UNC3886 has deployed malware using the victim's legitimate TLS certificate obtained from a compromised FortiGate device.

T1673
Virtual Machine Discovery
GroupUNC3886

UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

T1681
Search Threat Vendor Data
GroupUNC3886

UNC3886 has replaced indicators mentioned in open-source threat intelligence publications at times under a week after their release.

T1685
Disable or Modify Tools
GroupUNC3886

UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1690
Prevent Command History Logging
GroupUNC3886

UNC3886 has tampered with and disabled logging services on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.