Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupVOID MANTICORE | VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`. |
| T1005 Data from Local System |
GroupVOID MANTICORE | VOID MANTICORE has collected cached data and files from within the victim environment. |
| T1021.001 Remote Desktop Protocol |
GroupVOID MANTICORE | VOID MANTICORE has used RDP to move laterally within the victim environment. |
| T1027.015 Compression |
GroupVOID MANTICORE | VOID MANTICORE has compressed their payloads by leveraging zip files. |
| T1036.004 Masquerade Task or Service |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded as commonly used programs and services on Windows hosts. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1041 Exfiltration Over C2 Channel |
GroupVOID MANTICORE | VOID MANTICORE malware has exfiltrated collected data via Telegram bot C2 channels using encrypted communications. |
| T1047 Windows Management Instrumentation |
GroupVOID MANTICORE | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1059.001 PowerShell |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell to execute malware in victim environments. |
| T1059.006 Python |
GroupVOID MANTICORE | VOID MANTICORE has utilized Python scripts to execute its malicious payloads. |
| T1071.001 Web Protocols |
GroupVOID MANTICORE | VOID MANTICORE has utilized HTTPS for communication to C2 domains. |
| T1072 Software Deployment Tools |
GroupVOID MANTICORE | VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune. |
| T1074 Data Staged |
GroupVOID MANTICORE | VOID MANTICORE has staged compressed files in specified locations prior to exfiltration over C2. |
| T1078 Valid Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged valid accounts to log into VPN infrastructure. VOID MANTICORE has used compromised valid credentials to gain access to management infrastructure and enterprise control systems. VOID MANTICORE has also validated and tested authentication using compromised credentials prior to malicious actions. |
| T1078.002 Domain Accounts |
GroupVOID MANTICORE | VOID MANTICORE has used previously compromised Domain Administrator credentials to maintain persistent access. |
| T1078.004 Cloud Accounts |
GroupVOID MANTICORE | VOID MANTICORE has leveraged privileged cloud accounts to access cloud-based management consoles to include Microsoft Intune. VOID MANTICORE has also compromised existing accounts within the Microsoft Entra ID environment. |
| T1082 System Information Discovery |
GroupVOID MANTICORE | VOID MANTICORE has gathered system information and disseminated it back to C2. |
| T1087.002 Domain Account |
GroupVOID MANTICORE | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment. |
| T1098 Account Manipulation |
GroupVOID MANTICORE | VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access. |
| T1102 Web Service |
GroupVOID MANTICORE | VOID MANTICORE has utilized Telegram API for C2. |
| T1105 Ingress Tool Transfer |
GroupVOID MANTICORE | VOID MANTICORE has deployed additional payloads from dedicated C2 servers. VOID MANTICORE has also downloaded legitimate tools and software from publicly available services. VOID MANTICORE had utilized VeraCrypt a legitimate disk encrypting utility that was downloaded directly from the website. |
| T1110 Brute Force |
GroupVOID MANTICORE | VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure. |
| T1110.001 Password Guessing |
GroupVOID MANTICORE | VOID MANTICORE has conducted password guessing to gain initial access. |
| T1110.004 Credential Stuffing |
GroupVOID MANTICORE | VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments. |
| T1113 Screen Capture |
GroupVOID MANTICORE | VOID MANTICORE has captured screen content during an active Zoom session. |
| T1114.002 Remote Email Collection |
GroupVOID MANTICORE | VOID MANTICORE has gathered victim email-content from victim servers. |
| T1119 Automated Collection |
GroupVOID MANTICORE | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems. |
| T1123 Audio Capture |
GroupVOID MANTICORE | VOID MANTICORE has gathered audio during a Zoom session. |
| T1125 Video Capture |
GroupVOID MANTICORE | VOID MANTICORE has collected video from compromised victim devices. |
| T1133 External Remote Services |
GroupVOID MANTICORE | VOID MANTICORE has leveraged public facing VPN infrastructure to gain initial access to victim environments. |
| T1190 Exploit Public-Facing Application |
GroupVOID MANTICORE | VOID MANTICORE has exploited public facing vulnerabilities within victim environments to include SharePoint CVE-2019-0604. |
| T1199 Trusted Relationship |
GroupVOID MANTICORE | VOID MANTICORE has targeted IT and service providers in an effort to obtain credentials, relying largely on compromised VPN accounts for initial access. |
| T1204.002 Malicious File |
GroupVOID MANTICORE | VOID MANTICORE has delivered malicious payloads that initiate through user execution to include interaction with a masqueraded file. VOID MANTICORE has used trojanized application lures to induce targets into executing malware enabling persistent surveillance. |
| T1213.002 Sharepoint |
GroupVOID MANTICORE | VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data. |
| T1219.002 Remote Desktop Software |
GroupVOID MANTICORE | VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once. |
| T1484.001 Group Policy Modification |
GroupVOID MANTICORE | VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file. |
| T1485 Data Destruction |
GroupVOID MANTICORE | VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them. |
| T1486 Data Encrypted for Impact |
GroupVOID MANTICORE | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts. |
| T1490 Inhibit System Recovery |
GroupVOID MANTICORE | VOID MANTICORE has deleted virtual machines directly from the virtualization platform. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupVOID MANTICORE | VOID MANTICORE has created Windows Registry entries to autorun stage two malware payloads to maintain persistence. |
| T1552.002 Credentials in Registry |
GroupVOID MANTICORE | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM. |
| T1560.001 Archive via Utility |
GroupVOID MANTICORE | VOID MANTICORE has stored collected data in a password protected compressed file prior to exfiltration. |
| T1561.001 Disk Content Wipe |
GroupVOID MANTICORE | VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers. VOID MANTICORE has also utilized legitimate remote disk wiping commands. |
| T1561.002 Disk Structure Wipe |
GroupVOID MANTICORE | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files. |
| T1564.003 Hidden Window |
GroupVOID MANTICORE | VOID MANTICORE has utilized PowerShell scripts that run without notifying the user of its execution to include `-nop -w hidden- ep bypass -enc`. |
| T1566 Phishing |
GroupVOID MANTICORE | VOID MANTICORE has emailed victims threatening messages. VOID MANTICORE has used phishing as an initial access vector. |
| T1572 Protocol Tunneling |
GroupVOID MANTICORE | VOID MANTICORE has used tunneling tools to facilitate destructive attacks on compromised devices. |
| T1583.001 Domains |
GroupVOID MANTICORE | VOID MANTICORE has registered domains for messaging purposes. VOID MANTICORE has created typosquatted domains and sub-domains in attempts to avoid detection or draw suspicion. VOID MANTICORE has also purchased domains leveraging cryptocurrency platforms to include LiteCoin and Ramzinex. VOID MANTICORE has registered and rotated domains to support public-facing dissemination infrastructure, replacing disrupted domains with new registrations. |
| T1583.003 Virtual Private Server |
GroupVOID MANTICORE | VOID MANTICORE has utilized VPS solutions for C2. |
| T1583.004 Server |
GroupVOID MANTICORE | VOID MANTICORE has leveraged backend servers within Iran. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.