ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1571
Non-Standard Port
CampaignOperation Wocao

During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000.

T1571
Non-Standard Port
CampaignQuad7 Activity

Quad7 Activity has used non-standard TCP ports – such as 7777, 11288, 63256, 63210, 3256, and 3556 for C2.

T1572
Protocol Tunneling
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors utilized ngrok tunnels to deliver PowerShell payloads.

T1572
Protocol Tunneling
CampaignCutting Edge

During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS.

T1572
Protocol Tunneling
CampaignC0032

During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment.

T1572
Protocol Tunneling
CampaignC0027

During C0027, Scattered Spider used SSH tunneling in targeted environments.

T1572
Protocol Tunneling
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler software to establish a “Yamux” TLS-based C2 channel with an external server(s).

T1572
Protocol Tunneling
CampaignCostaRicto

During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain.

T1573
Encrypted Channel
CampaignKV Botnet Activity

KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation.

T1573
Encrypted Channel
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic.

T1573.001
Symmetric Cryptography
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server.

T1573.001
Symmetric Cryptography
CampaignFrankenstein

During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC.

T1573.001
Symmetric Cryptography
CampaignRedPenguin

During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages.

T1573.001
Symmetric Cryptography
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL communication module supports three commands to conduct the following actions: send implant data, execute shellcode, and terminate itself.

T1573.002
Asymmetric Cryptography
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho used SSL for network communication.

T1573.002
Asymmetric Cryptography
CampaignC0021

During C0021, the threat actors used SSL via TCP port 443 for C2 communications.

T1573.002
Asymmetric Cryptography
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1573.002
Asymmetric Cryptography
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers.

T1573.002
Asymmetric Cryptography
CampaignOperation Wocao

During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.

T1574
Hijack Execution Flow
CampaignPikabot Distribution February 2024

Pikabot Distribution February 2024 utilized a tampered legitimate executable, `grepWinNP3.exe`, for its first stage Pikabot loader, modifying the open-source tool to execute malicious code when launched.

T1574
Hijack Execution Flow
CampaignC0017

During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries.

T1574.001
DLL
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda used DLL search order hijacking on vulnerable applications to install PlugX payloads during RedDelta Modified PlugX Infection Chain Operations.

T1574.001
DLL
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus splits functionally across multiple .dll files using export functions, such as DLLGetClassObject, to execute code from an embedded .dll file within another .dll file. AppleJeus has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence.

T1574.001
DLL
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the legitimate Windows services `IKEEXT` and `PrintNotify` to side-load malicious DLLs.

T1574.001
DLL
CampaignAPT41 DUST

APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller.

T1574.011
Services Registry Permissions Weakness
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a batch file that modified the COMSysApp service to load a malicious ipnet.dll payload and to load a DLL into the `svchost.exe` process.

T1578.002
Create Cloud Instance
CampaignC0027

During C0027, Scattered Spider used access to the victim's Azure tenant to create Azure VMs.

T1583.001
Domains
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.

T1583.001
Domains
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors registered C2 domains to spoof legitimate Microsoft domains.

T1583.001
Domains
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda registered adversary-controlled domains during RedDelta Modified PlugX Infection Chain Operations that were re-registrations of expired domains.

T1583.001
Domains
CampaignOperation Honeybee

During Operation Honeybee, threat actors registered domains for C2.

T1583.001
Domains
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure.

T1583.001
Domains
CampaignIndian Critical Infrastructure Intrusions

During Indian Critical Infrastructure Intrusions, RedEcho registered domains spoofing Indian critical infrastructure entities.

T1583.001
Domains
CampaignOperation Spalax

For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit.

T1583.001
Domains
CampaignC0021

For C0021, the threat actors registered domains for use in C2.

T1583.001
Domains
CampaignOperation Ghost

For Operation Ghost, APT29 registered domains for use in C2 including some crafted to appear as existing legitimate domains.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

T1583.001
Domains
CampaignFunnyDream

For FunnyDream, the threat actors registered a variety of domains.

T1583.001
Domains
CampaignC0010

For C0010, UNC3890 actors established domains that appeared to be legitimate services and entities, such as LinkedIn, Facebook, Office 365, and Pfizer.

T1583.001
Domains
CampaignC0011

For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India.

T1583.001
Domains
CampaignC0026

For C0026, the threat actors re-registered expired C2 domains previously used for ANDROMEDA malware.

T1583.001
Domains
CampaignCostaRicto

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

T1583.003
Virtual Private Server
CampaignKV Botnet Activity

KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware.

T1583.003
Virtual Private Server
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors acquired VPS for use in C2.

T1583.003
Virtual Private Server
CampaignC0032

During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure.

T1583.003
Virtual Private Server
CampaignSPACEHOP Activity

SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network.

T1583.003
Virtual Private Server
CampaignArcaneDoor

ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control.

T1583.003
Virtual Private Server
CampaignFLORAHOX Activity

FLORAHOX Activity has used acquired Virtual Private Servers as control systems for the ORB network.

T1583.004
Server
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.

T1583.004
Server
CampaignOperation Honeybee

For Operation Honeybee, at least one identified persona was used to register for a free account for a control server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.