Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.006 Web Services |
GroupVOID MANTICORE | VOID MANTICORE has obtained access to commercial VPN services to launch malicious activity. VOID MANTICORE has also leveraged Starlink internet services. VOID MANTICORE has used operator-controlled Telegram bots and channels as C2 infrastructure. |
| T1585.001 Social Media Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created Telegram Accounts. VOID MANTICORE has also leveraged online personas such as Handala Hack, Karma, and Homeland Justice on social media to include Telegram. VOID MANTICORE has established and maintained social media accounts on Twitter/X and Telegram to amplify operational claims and stolen data disclosures. |
| T1585.002 Email Accounts |
GroupVOID MANTICORE | VOID MANTICORE has created email accounts to send threatening messages to victims to include ‘Handala_Team[@]outlook[.]com’. |
| T1587.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper. |
| T1588.001 Malware |
GroupVOID MANTICORE | VOID MANTICORE has developed or obtained trojanized applications used for persistent surveillance of targeted individuals. |
| T1588.002 Tool |
GroupVOID MANTICORE | VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities. |
| T1589 Gather Victim Identity Information |
GroupVOID MANTICORE | VOID MANTICORE has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks. |
| T1595.002 Vulnerability Scanning |
GroupVOID MANTICORE | VOID MANTICORE has scanned victim environments for susceptibility to vulnerability exploitation. |
| T1651 Cloud Administration Command |
GroupVOID MANTICORE | VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices. |
| T1657 Financial Theft |
GroupVOID MANTICORE | VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency. |
| T1679 Selective Exclusion |
GroupVOID MANTICORE | VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection. |
| T1684.001 Impersonation |
GroupVOID MANTICORE | VOID MANTICORE has impersonated individuals familiar to the victim and technical support associated with social messaging services. |
| T1686.003 Windows Host Firewall |
GroupVOID MANTICORE | VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.