ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1051×

57 examples

TechniqueUsed byProcedure example
T1608.002
Upload Tool
GroupMedusa Group

Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.

T1650
Acquire Access
GroupMedusa Group

Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).

T1652
Device Driver Discovery
GroupMedusa Group

Medusa Group has queried drivers on the victim device through the command `driverquery`.

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

T1686
Disable or Modify System Firewall
GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

T1690
Prevent Command History Logging
GroupMedusa Group

Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.