ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
GroupFIN6

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1047
Windows Management Instrumentation
GroupFIN7

FIN7 has used WMI to install malware on targeted systems.

T1047
Windows Management Instrumentation
GroupSandworm Team

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1047
Windows Management Instrumentation
GroupTA2541

TA2541 has used WMI to query targeted systems for security products.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1047
Windows Management Instrumentation
GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

T1047
Windows Management Instrumentation
GroupLeviathan

Leviathan has used WMI for execution.

T1047
Windows Management Instrumentation
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe to set environment variables.

T1047
Windows Management Instrumentation
GroupLotus Blossom

Lotus Blossom has used WMI to enable lateral movement.

T1047
Windows Management Instrumentation
GroupStealth Falcon

Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI).

T1047
Windows Management Instrumentation
GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1047
Windows Management Instrumentation
GroupCinnamon Tempest

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1047
Windows Management Instrumentation
GroupMirrorFace

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1047
Windows Management Instrumentation
GroupDeep Panda

The Deep Panda group is known to utilize WMI for lateral movement.

T1047
Windows Management Instrumentation
GroupEmber Bear

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.

T1047
Windows Management Instrumentation
GroupWindshift

Windshift has used WMI to collect information about target machines.

T1047
Windows Management Instrumentation
GroupToddyCat

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1047
Windows Management Instrumentation
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1047
Windows Management Instrumentation
GroupINC Ransom

INC Ransom has used WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupEarth Lusca

Earth Lusca used a VBA script to execute WMI.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupVelvet Ant

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1047
Windows Management Instrumentation
GroupVOID MANTICORE

VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.

T1047
Windows Management Instrumentation
GroupMagic Hound

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

T1047
Windows Management Instrumentation
GroupThreat Group-3390

A Threat Group-3390 tool can use WMI to execute a binary.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

T1048
Exfiltration Over Alternative Protocol
GroupTeamTNT

TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL.

T1048
Exfiltration Over Alternative Protocol
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupStorm-1811

Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP).

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupCURIUM

CURIUM has used SMTPS to exfiltrate collected data from victims.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupMirrorFace

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupAPT28

APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupSalt Typhoon

Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT32

APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupThrip

Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupWizard Spider

Wizard Spider has exfiltrated victim information using FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.