ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1053×

42 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupStorm-0501

Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.

T1003.006
DCSync
GroupStorm-0501

Storm-0501 has utilized DCSync to extract credentials from victims.

T1021.006
Windows Remote Management
GroupStorm-0501

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.

T1021.007
Cloud Services
GroupStorm-0501

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.

T1027.002
Software Packing
GroupStorm-0501

Storm-0501 has used Themida to pack Cobalt Strike payloads.

T1036.004
Masquerade Task or Service
GroupStorm-0501

Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe.

T1053.005
Scheduled Task
GroupStorm-0501

Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware.

T1057
Process Discovery
GroupStorm-0501

Storm-0501 has discovered running processes through `tasklist.exe`.

T1059.001
PowerShell
GroupStorm-0501

Storm-0501 has leveraged PowerShell to execute commands and scripts.

T1059.009
Cloud API
GroupStorm-0501

Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments.

T1078.004
Cloud Accounts
GroupStorm-0501

Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment.

T1082
System Information Discovery
GroupStorm-0501

Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint.

T1087.002
Domain Account
GroupStorm-0501

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

T1087.004
Cloud Account
GroupStorm-0501

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

T1098.001
Additional Cloud Credentials
GroupStorm-0501

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

T1098.003
Additional Cloud Roles
GroupStorm-0501

Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions.

T1110
Brute Force
GroupStorm-0501

Storm-0501 has leveraged brute force attacks to obtain credentials.

T1190
Exploit Public-Facing Application
GroupStorm-0501

Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

T1218.010
Regsvr32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe.

T1218.011
Rundll32
GroupStorm-0501

Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe.

T1219.002
Remote Desktop Software
GroupStorm-0501

Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io.

T1482
Domain Trust Discovery
GroupStorm-0501

Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery.

T1484.001
Group Policy Modification
GroupStorm-0501

Storm-0501 distributed Group Policy Objects to tamper with security products.

T1484.002
Trust Modification
GroupStorm-0501

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.

T1485
Data Destruction
GroupStorm-0501

Storm-0501 has destroyed data and backup files.

T1486
Data Encrypted for Impact
GroupStorm-0501

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.

T1490
Inhibit System Recovery
GroupStorm-0501

Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`,
`Microsoft.Compute/restorePointCollections/delete`,
`Microsoft.Storage/storageAccounts/delete`, and
`Microsoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete`.

T1518.001
Security Software Discovery
GroupStorm-0501

Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`.

T1526
Cloud Service Discovery
GroupStorm-0501

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.

T1530
Data from Cloud Storage
GroupStorm-0501

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.

T1537
Transfer Data to Cloud Account
GroupStorm-0501

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.

T1552.004
Private Keys
GroupStorm-0501

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.

T1555.005
Password Managers
GroupStorm-0501

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.

T1555.006
Cloud Secrets Management Stores
GroupStorm-0501

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.

T1556.009
Conditional Access Policies
GroupStorm-0501

Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1578.003
Delete Cloud Instance
GroupStorm-0501

Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions.

T1580
Cloud Infrastructure Discovery
GroupStorm-0501

Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources.

T1587.003
Digital Certificates
GroupStorm-0501

Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure.

T1588.006
Vulnerabilities
GroupStorm-0501

Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203).

T1614.001
System Language Discovery
GroupStorm-0501

Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from.

T1657
Financial Theft
GroupStorm-0501

Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.