ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1036.008
Masquerade File Type
GroupBlackByte

BlackByte masqueraded configuration files containing encryption keys as PNG files.

T1036.008
Masquerade File Type
GroupVolt Typhoon

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

T1036.008
Masquerade File Type
GroupMustang Panda

Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware.

T1036.008
Masquerade File Type
GroupMirrorFace

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

T1036.010
Masquerade Account Name
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1036.010
Masquerade Account Name
GroupDragonfly

Dragonfly has created accounts disguised as legitimate backup and service accounts as well as an email administration account.

T1036.010
Masquerade Account Name
GroupStorm-1811

Storm-1811 has created Microsoft Teams accounts that spoof IT support and helpdesk members for use in application and voice phishing.

T1036.010
Masquerade Account Name
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1037
Boot or Logon Initialization Scripts
GroupAPT41

APT41 used a hidden shell script in `/etc/rc.d/init.d` to leverage the `ADORE.XSEC`backdoor and `Adore-NG` rootkit.

T1037
Boot or Logon Initialization Scripts
GroupRocke

Rocke has installed an "init.d" startup script to maintain persistence.

T1037
Boot or Logon Initialization Scripts
GroupUNC3886

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

T1037
Boot or Logon Initialization Scripts
GroupAPT29

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

T1037.001
Logon Script (Windows)
GroupAPT28

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1037.001
Logon Script (Windows)
GroupCobalt Group

Cobalt Group has added persistence by registering the file name for the next stage malware under HKCU\Environment\UserInitMprLogonScript.

T1037.004
RC Scripts
GroupUNC3886

UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence.

T1037.004
RC Scripts
GroupAPT29

APT29 has installed a run command on a compromised system to enable malware execution on system startup.

T1037.004
RC Scripts
GroupVelvet Ant

Velvet Ant used a modified `/etc/rc.local` file on compromised F5 BIG-IP devices to maintain persistence.

T1039
Data from Network Shared Drive
GroupmenuPass

menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.

T1039
Data from Network Shared Drive
GroupGamaredon Group

Gamaredon Group malware has collected Microsoft Office documents from mapped network drives.

T1039
Data from Network Shared Drive
GroupRedCurl

RedCurl has collected data about network drives.

T1039
Data from Network Shared Drive
GroupChimera

Chimera has collected data of interest from network shares.

T1039
Data from Network Shared Drive
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from file shares.

T1039
Data from Network Shared Drive
GroupAPT28

APT28 has collected files from network shared drives.

T1039
Data from Network Shared Drive
GroupFox Kitten

Fox Kitten has searched network shares to access sensitive documents.

T1039
Data from Network Shared Drive
GroupSowbug

Sowbug extracted Word documents from a file server on a victim network.

T1040
Network Sniffing
GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

T1040
Network Sniffing
GroupSalt Typhoon

Salt Typhoon has used a variety of tools and techniques to capture packet data between network interfaces.

T1040
Network Sniffing
GroupSandworm Team

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

T1040
Network Sniffing
GroupUNC3886

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

T1040
Network Sniffing
GroupDarkVishnya

DarkVishnya used network sniffing to obtain login data.

T1040
Network Sniffing
GroupAPT28

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

T1040
Network Sniffing
GroupVelvet Ant

Velvet Ant has used a custom tool, "VELVETTAP", to perform packet capture from compromised F5 BIG-IP devices.

T1040
Network Sniffing
GroupAPT33

APT33 has used SniffPass to collect credentials by sniffing network traffic.

T1041
Exfiltration Over C2 Channel
GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1041
Exfiltration Over C2 Channel
GroupGALLIUM

GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.

T1041
Exfiltration Over C2 Channel
GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKimsuky

Kimsuky has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupAPT32

APT32's backdoor has exfiltrated data using the already opened channel with its C&C server.

T1041
Exfiltration Over C2 Channel
GroupMuddyWater

MuddyWater has used C2 infrastructure to receive exfiltrated data.

T1041
Exfiltration Over C2 Channel
GroupGamaredon Group

A Gamaredon Group file stealer can transfer collected files to a hardcoded C2 server.

T1041
Exfiltration Over C2 Channel
GroupSandworm Team

Sandworm Team has sent system information to its C2 server using HTTP.

T1041
Exfiltration Over C2 Channel
GroupCURIUM

CURIUM has used IMAP and SMTPS for exfiltration via tools such as IMAPLoader.

T1041
Exfiltration Over C2 Channel
GroupMustang Panda

Mustang Panda has exfiltrated stolen data and files to its C2 server.

T1041
Exfiltration Over C2 Channel
GroupZIRCONIUM

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1041
Exfiltration Over C2 Channel
GroupScattered Spider

Scattered Spider has exfiltrated data from compromised VMware vCenter servers through an established C2 channel using the Teleport remote access tool.

T1041
Exfiltration Over C2 Channel
GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1041
Exfiltration Over C2 Channel
GroupHigaisa

Higaisa exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
GroupKe3chang

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

T1041
Exfiltration Over C2 Channel
GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.