Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMedusa Group | Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials. |
| T1003.003 NTDS |
GroupMedusa Group | Medusa Group has accessed the ntds.dit file to engage in credential dumping. |
| T1016 System Network Configuration Discovery |
GroupMedusa Group | Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`. |
| T1018 Remote System Discovery |
GroupMedusa Group | Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network. |
| T1021.001 Remote Desktop Protocol |
GroupMedusa Group | Medusa Group has used RDP to conduct lateral movement and exfiltrate data. Medusa Group has also utilized the Windows executable `mstsc.exe` for RDP activities through the command `mstsc.exe /v:{hostname/ip}`. |
| T1027.002 Software Packing |
GroupMedusa Group | Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard. |
| T1027.010 Command Obfuscation |
GroupMedusa Group | Medusa Group has obfuscated PowerShell scripts with Base64 encoding. Medusa Group has also obfuscated the code of dropped kernel drivers using a software known as Safengine Shielden which randomized the code through code mutations and then leveraged an embedded virtual machine interpreter to execute the code. |
| T1033 System Owner/User Discovery |
GroupMedusa Group | Medusa Group has utilized PsExec to execute `quser` to discover the user session information. |
| T1046 Network Service Discovery |
GroupMedusa Group | Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services. |
| T1047 Windows Management Instrumentation |
GroupMedusa Group | Medusa Group has utilized Windows Management Instrumentation to query system information. |
| T1057 Process Discovery |
GroupMedusa Group | Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094. |
| T1059.001 PowerShell |
GroupMedusa Group | Medusa Group has leveraged PowerShell for execution and defense evasion. Medusa Group has also utilized PowerShell to execute a bitsadmin transfer from file hosting site. |
| T1059.003 Windows Command Shell |
GroupMedusa Group | Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities. |
| T1069.002 Domain Groups |
GroupMedusa Group | Medusa Group has utilized the `net group` command to query domain groups within the victim environment. |
| T1070.003 Clear Command History |
GroupMedusa Group | Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`. |
| T1070.004 File Deletion |
GroupMedusa Group | Medusa Group has deleted previously installed tools. |
| T1071.001 Web Protocols |
GroupMedusa Group | Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS). |
| T1072 Software Deployment Tools |
GroupMedusa Group | Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy. |
| T1078 Valid Accounts |
GroupMedusa Group | Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec. |
| T1082 System Information Discovery |
GroupMedusa Group | Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`. |
| T1083 File and Directory Discovery |
GroupMedusa Group | Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services. |
| T1087.001 Local Account |
GroupMedusa Group | Medusa Group has leveraged `net user` for account discovery. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1105 Ingress Tool Transfer |
GroupMedusa Group | Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services. Medusa Group has also engaged in “Bring Your Own Vulnerable Driver” (BYOVD) and downloaded vulnerable or signed drivers to the victim environment to disable security tools. |
| T1106 Native API |
GroupMedusa Group | Medusa Group has leveraged Windows Native API functions to execute payloads. |
| T1112 Modify Registry |
GroupMedusa Group | Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access. |
| T1135 Network Share Discovery |
GroupMedusa Group | Medusa Group has identified network shares using `cmd.exe /c net share`. |
| T1136.002 Domain Account |
GroupMedusa Group | Medusa Group has created a domain account within the victim environment. |
| T1190 Exploit Public-Facing Application |
GroupMedusa Group | Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access. Medusa Group has also utilized CVE-2024-1709 in ScreenConnect, and CVE-2023-48788 in Fortinet EMS for initial access to victim environments. |
| T1218.014 MMC |
GroupMedusa Group | Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`. |
| T1219 Remote Access Tools |
GroupMedusa Group | Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1489 Service Stop |
GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| T1490 Inhibit System Recovery |
GroupMedusa Group | Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1505.003 Web Shell |
GroupMedusa Group | Medusa Group has utilized webshells to an exploited Microsoft Exchange Server. |
| T1518.001 Security Software Discovery |
GroupMedusa Group | Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1529 System Shutdown/Reboot |
GroupMedusa Group | Medusa Group has manually turned off and encrypted virtual machines. |
| T1543.003 Windows Service |
GroupMedusa Group | Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices. |
| T1548.002 Bypass User Account Control |
GroupMedusa Group | Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface. |
| T1553.002 Code Signing |
GroupMedusa Group | Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools. |
| T1559.001 Component Object Model |
GroupMedusa Group | Medusa Group has leveraged Component Object Model (COM) to bypass UAC. |
| T1564.003 Hidden Window |
GroupMedusa Group | Medusa Group has utilized the `ShowWindow` API function to hide the current window. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMedusa Group | Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1570 Lateral Tool Transfer |
GroupMedusa Group | Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment. |
| T1573.002 Asymmetric Cryptography |
GroupMedusa Group | Medusa Group has used HTTPS for command and control. |
| T1583.006 Web Services |
GroupMedusa Group | Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions. |
| T1585.001 Social Media Accounts |
GroupMedusa Group | Medusa Group has created social media accounts including Telegram and X to publicize their activities. |
| T1585.002 Email Accounts |
GroupMedusa Group | Medusa Group has created email accounts used in ransomware negotiations. |
| T1588.002 Tool |
GroupMedusa Group | Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.