ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupMirrorFace

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.

T1027.013
Encrypted/Encoded File
GroupDarkhotel

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1027.013
Encrypted/Encoded File
GroupWhitefly

Whitefly has encrypted the payload used for C2.

T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1027.013
Encrypted/Encoded File
GroupMalteiro

Malteiro has used scripts encoded in Base64 certificates to distribute malware to victims.

T1027.013
Encrypted/Encoded File
GroupMetador

Metador has encrypted their payloads.

T1027.013
Encrypted/Encoded File
GroupFox Kitten

Fox Kitten has base64 encoded payloads to avoid detection.

T1027.013
Encrypted/Encoded File
GroupAPT-C-36

APT-C-36 has used encoded and obfuscated files, images, and executables.

T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1027.013
Encrypted/Encoded File
GroupTransparent Tribe

Transparent Tribe has dropped encoded executables on compromised hosts.

T1027.013
Encrypted/Encoded File
GroupMoonstone Sleet

Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion.

T1027.013
Encrypted/Encoded File
GroupInception

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.

T1027.013
Encrypted/Encoded File
GroupMagic Hound

Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES.

T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.013
Encrypted/Encoded File
GroupAPT33

APT33 has used base64 to encode payloads.

T1027.013
Encrypted/Encoded File
GroupAPT19

APT19 used Base64 to obfuscate payloads.

T1027.015
Compression
GroupKimsuky

Kimsuky has delivered malicious payloads within Zip archives.

T1027.015
Compression
GroupGamaredon Group

Gamaredon Group has delivered malicious payloads within compressed archives and zip files.

T1027.015
Compression
GroupTA2541

TA2541 has used compressed and char-encoded scripts in operations.

T1027.015
Compression
GroupHigaisa

Higaisa used Base64 encoded compressed payloads.

T1027.015
Compression
GroupLeviathan

Leviathan has obfuscated code using gzip compression.

T1027.015
Compression
GroupMofang

Mofang has compressed the ShimRat executable within malicious email attachments.

T1027.015
Compression
GroupMolerats

Molerats has delivered compressed executables within ZIP files to victims.

T1027.015
Compression
GroupVOID MANTICORE

VOID MANTICORE has compressed their payloads by leveraging zip files.

T1027.015
Compression
GroupWIRTE

WIRTE has compressed malicious files within RAR and ZIP archives for obfuscation.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1027.016
Junk Code Insertion
GroupKimsuky

Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection.

T1027.016
Junk Code Insertion
GroupAPT32

APT32 includes garbage code to mislead anti-malware software and researchers.

T1027.016
Junk Code Insertion
GroupGamaredon Group

Gamaredon Group has obfuscated .NET executables by inserting junk code.

T1027.016
Junk Code Insertion
GroupFIN7

FIN7 has used random junk code to obfuscate malware code.

T1027.016
Junk Code Insertion
GroupMustang Panda

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1027.016
Junk Code Insertion
GroupAPT-C-36

APT-C-36 has used junk characters to obfuscate malicious scripts.

T1029
Scheduled Transfer
GroupHigaisa

Higaisa sent the victim computer identifier in a User-Agent string back to the C2 server every 10 minutes.

T1030
Data Transfer Size Limits
GroupAPT41

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

T1030
Data Transfer Size Limits
GroupLuminousMoth

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

T1030
Data Transfer Size Limits
GroupAPT28

APT28 has split archived exfiltration files into chunks smaller than 1MB.

T1030
Data Transfer Size Limits
GroupPlay

Play has split victims' files into chunks for exfiltration.

T1030
Data Transfer Size Limits
GroupThreat Group-3390

Threat Group-3390 actors have split RAR files for exfiltration into parts.

T1033
System Owner/User Discovery
GroupAPT38

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

T1033
System Owner/User Discovery
GroupGALLIUM

GALLIUM used whoami and query user to obtain information about the victim user.

T1033
System Owner/User Discovery
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

T1033
System Owner/User Discovery
GroupKimsuky

Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1033
System Owner/User Discovery
GroupPatchwork

Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server.

T1033
System Owner/User Discovery
GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

T1033
System Owner/User Discovery
GroupDragonfly

Dragonfly used the command query user on victim hosts.

T1033
System Owner/User Discovery
GroupAPT32

APT32 collected the victim's username and executed the whoami command on the victim's machine. APT32 executed shellcode to collect the username on the victim's machine.

T1033
System Owner/User Discovery
GroupHAFNIUM

HAFNIUM has used `whoami` to gather user information.

T1033
System Owner/User Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s username.

T1033
System Owner/User Discovery
GroupGamaredon Group

A Gamaredon Group file stealer can gather the victim's username to send to a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.