Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1608.002 Upload Tool |
GroupMedusa Group | Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise. |
| T1650 Acquire Access |
GroupMedusa Group | Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs). |
| T1652 Device Driver Discovery |
GroupMedusa Group | Medusa Group has queried drivers on the victim device through the command `driverquery`. |
| T1657 Financial Theft |
GroupMedusa Group | Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
| T1686 Disable or Modify System Firewall |
GroupMedusa Group | Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions. |
| T1690 Prevent Command History Logging |
GroupMedusa Group | Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.