Real-world descriptions of how a group, tool or campaign used a technique.
42 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupStorm-0501 | Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1003.006 DCSync |
GroupStorm-0501 | Storm-0501 has utilized DCSync to extract credentials from victims. |
| T1021.006 Windows Remote Management |
GroupStorm-0501 | Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution. |
| T1021.007 Cloud Services |
GroupStorm-0501 | Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment. |
| T1027.002 Software Packing |
GroupStorm-0501 | Storm-0501 has used Themida to pack Cobalt Strike payloads. |
| T1036.004 Masquerade Task or Service |
GroupStorm-0501 | Storm-0501 has utilized Rclone masqueraded as svhost.exe and scvhost.exe. |
| T1053.005 Scheduled Task |
GroupStorm-0501 | Storm-0501 had used a scheduled task named “SysUpdate” that was registered via GPO on devices in the network to distribute the Embargo ransomware. |
| T1057 Process Discovery |
GroupStorm-0501 | Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1059.001 PowerShell |
GroupStorm-0501 | Storm-0501 has leveraged PowerShell to execute commands and scripts. |
| T1059.009 Cloud API |
GroupStorm-0501 | Storm-0501 has leveraged Cloud CLI to execute commands and exfiltrate data from compromised environments. |
| T1078.004 Cloud Accounts |
GroupStorm-0501 | Storm-0501 has leveraged compromised accounts to access Microsoft Entra Connect, which was used to synchronize on-premises identities and Microsoft Entra identities, allowing users to sign into both environments with the same password. Storm-0501 has also used the victim Global Administrator account that lacked any registered MFA method to access victim cloud environments. Storm-0501 has leveraged Storage Account Access Keys within the victim environment. |
| T1082 System Information Discovery |
GroupStorm-0501 | Storm-0501 has leveraged native Windows tools and commands such as `systeminfo` and open-source tools including OSQuery and ossec-win32 to query details about the endpoint. |
| T1087.002 Domain Account |
GroupStorm-0501 | Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
| T1087.004 Cloud Account |
GroupStorm-0501 | Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| T1098.001 Additional Cloud Credentials |
GroupStorm-0501 | Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method. |
| T1098.003 Additional Cloud Roles |
GroupStorm-0501 | Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions. |
| T1110 Brute Force |
GroupStorm-0501 | Storm-0501 has leveraged brute force attacks to obtain credentials. |
| T1190 Exploit Public-Facing Application |
GroupStorm-0501 | Storm-0501 has exploited N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1218.010 Regsvr32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files using regsvr32.exe. |
| T1218.011 Rundll32 |
GroupStorm-0501 | Storm-0501 has launched Cobalt Strike Beacon files with rundll32.exe. |
| T1219.002 Remote Desktop Software |
GroupStorm-0501 | Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io. |
| T1482 Domain Trust Discovery |
GroupStorm-0501 | Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery. |
| T1484.001 Group Policy Modification |
GroupStorm-0501 | Storm-0501 distributed Group Policy Objects to tamper with security products. |
| T1484.002 Trust Modification |
GroupStorm-0501 | Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use. |
| T1485 Data Destruction |
GroupStorm-0501 | Storm-0501 has destroyed data and backup files. |
| T1486 Data Encrypted for Impact |
GroupStorm-0501 | Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware. |
| T1490 Inhibit System Recovery |
GroupStorm-0501 | Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration. Storm-0501 has also impacted Azure resources through the targeting of `Microsoft.Compute/snapshots/delete`, |
| T1518.001 Security Software Discovery |
GroupStorm-0501 | Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`. |
| T1526 Cloud Service Discovery |
GroupStorm-0501 | Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies. |
| T1530 Data from Cloud Storage |
GroupStorm-0501 | Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration. |
| T1537 Transfer Data to Cloud Account |
GroupStorm-0501 | Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI. |
| T1552.004 Private Keys |
GroupStorm-0501 | Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation. |
| T1555.005 Password Managers |
GroupStorm-0501 | Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1. |
| T1555.006 Cloud Secrets Management Stores |
GroupStorm-0501 | Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`. |
| T1556.009 Conditional Access Policies |
GroupStorm-0501 | Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1578.003 Delete Cloud Instance |
GroupStorm-0501 | Storm-0501 has conducted mass deletion of cloud data stores and resources from Azure subscriptions. |
| T1580 Cloud Infrastructure Discovery |
GroupStorm-0501 | Storm-0501 has enumerated compromised cloud environments to identify critical assets, data stores, and back resources. |
| T1587.003 Digital Certificates |
GroupStorm-0501 | Storm-0501 has utilized their own self-signed TLS certificate “Microsoft IT TLS CA 5” with their infrastructure. |
| T1588.006 Vulnerabilities |
GroupStorm-0501 | Storm-0501 has obtained capabilities to exploit N-day vulnerabilities associated with public facing services to gain initial access to victim environments to include Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler “Citrix Bleed” (CVE-2023-4966), and Adobe ColdFusion 2016 (CVE-2023-29300 or CVE-2023-38203). |
| T1614.001 System Language Discovery |
GroupStorm-0501 | Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from. |
| T1657 Financial Theft |
GroupStorm-0501 | Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.