ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1054×

43 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMirrorFace

MirrorFace has dumped LSASS memory for credential access.

T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1005
Data from Local System
GroupMirrorFace

MirrorFace gathered data and files of interest from victim's systems.

T1007
System Service Discovery
GroupMirrorFace

MirrorFace has used Tasklist for discovery post compromise.

T1016
System Network Configuration Discovery
GroupMirrorFace

MirrorFace has used ipconfig for reconnaissance.

T1018
Remote System Discovery
GroupMirrorFace

MirrorFace has used Ping for system discovery.

T1021.001
Remote Desktop Protocol
GroupMirrorFace

MirrorFace has used RDP to exfiltrate files of interest.

T1021.002
SMB/Windows Admin Shares
GroupMirrorFace

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1027.013
Encrypted/Encoded File
GroupMirrorFace

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.

T1033
System Owner/User Discovery
GroupMirrorFace

MirrorFace has used Windows native tools to enumerate user information.

T1036.008
Masquerade File Type
GroupMirrorFace

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

T1047
Windows Management Instrumentation
GroupMirrorFace

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupMirrorFace

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.

T1057
Process Discovery
GroupMirrorFace

MirrorFace has used Tasklist on compromised hosts for discovery.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1059.005
Visual Basic
GroupMirrorFace

MirrorFace has used remote templates with VBA code in malware infection chains.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1071.002
File Transfer Protocols
GroupMirrorFace

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.

T1074.002
Remote Data Staging
GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

T1082
System Information Discovery
GroupMirrorFace

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.

T1083
File and Directory Discovery
GroupMirrorFace

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.

T1087.002
Domain Account
GroupMirrorFace

MirrorFace has used native Windows tools to obtain domain user information.

T1090
Proxy
GroupMirrorFace

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.

T1114.001
Local Email Collection
GroupMirrorFace

MirrorFace has exfiltrated stored emails from compromised hosts.

T1190
Exploit Public-Facing Application
GroupMirrorFace

MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1221
Template Injection
GroupMirrorFace

MirrorFace has used remote template injection to retrieve malicious payloads from the C2.

T1482
Domain Trust Discovery
GroupMirrorFace

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.

T1553.002
Code Signing
GroupMirrorFace

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.

T1556.002
Password Filter DLL
GroupMirrorFace

MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupMirrorFace

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.

T1566.002
Spearphishing Link
GroupMirrorFace

MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1587.001
Malware
GroupMirrorFace

MirrorFace has created and continued to develop custom strains of malware including LODEINFO.

T1588.002
Tool
GroupMirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

T1591
Gather Victim Org Information
GroupMirrorFace

MirrorFace has placed specific content in phishing emails to target members of particular political parties.

T1614.001
System Language Discovery
GroupMirrorFace

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.

T1684.001
Impersonation
GroupMirrorFace

MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department.

T1685
Disable or Modify Tools
GroupMirrorFace

MirrorFace has disabled Windows Defender in compromised environments.

T1685.005
Clear Windows Event Logs
GroupMirrorFace

MirrorFace has deleted Windows event logs.

T1686.003
Windows Host Firewall
GroupMirrorFace

MirrorFace can modify the system firewall to allow communication to certain ports.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.