ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1055×

63 examples

TechniqueUsed byProcedure example
T1583.006
Web Services
GroupVOID MANTICORE

VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure.

T1585.001
Social Media Accounts
GroupVOID MANTICORE

VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures.

T1585.002
Email Accounts
GroupVOID MANTICORE

VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’.

T1587.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper.

T1588.001
Malware
GroupVOID MANTICORE

VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals.

T1588.002
Tool
GroupVOID MANTICORE

VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.

T1589
Gather Victim Identity Information
GroupVOID MANTICORE

VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.

T1595.002
Vulnerability Scanning
GroupVOID MANTICORE

VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation.

T1651
Cloud Administration Command
GroupVOID MANTICORE

VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.

T1657
Financial Theft
GroupVOID MANTICORE

VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency.

T1679
Selective Exclusion
GroupVOID MANTICORE

VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection.

T1684.001
Impersonation
GroupVOID MANTICORE

VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services.

T1686.003
Windows Host Firewall
GroupVOID MANTICORE

VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.