ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1136.001
Local Account
GroupTeamTNT

TeamTNT has created local privileged users on victim machines.

T1136.001
Local Account
GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

T1136.001
Local Account
GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

T1136.001
Local Account
GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

T1136.001
Local Account
GroupWizard Spider

Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.

T1136.001
Local Account
GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1136.001
Local Account
GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

T1136.001
Local Account
MalwareHildegard

Hildegard has created a user named “monerodaemon”.

T1136.001
Local Account
MalwareS-Type

S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`.

T1136.001
Local Account
MalwareDarkGate

DarkGate creates a local user account, SafeMode, via net user commands.

T1136.001
Local Account
MalwareCarbanak

Carbanak can create a Windows account.

T1136.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has created user accounts.

T1136.001
Local Account
MalwareServHelper

ServHelper has created a new user named "supportaccount".

T1136.001
Local Account
MalwareCalisto

Calisto has the capability to add its own account to the victim's machine.

T1136.001
Local Account
MalwareGoldenSpy

GoldenSpy can create new users on an infected system.

T1136.001
Local Account
MalwareZxShell

ZxShell has a feature to create local user accounts.

T1136.001
Local Account
MalwareMis-Type

Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`.

T1136.001
Local Account
MalwareHiddenWasp

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

T1136.001
Local Account
ToolNet

The net user username \password commands in Net can be used to create a local account.

T1136.001
Local Account
ToolEmpire

Empire has a module for creating a local user if permissions allow.

T1136.001
Local Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create local system accounts.

T1136.001
Local Account
MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

T1136.002
Domain Account
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team created privileged domain accounts to be used for further exploitation and lateral movement.

T1136.002
Domain Account
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team created two new accounts, “admin” and “система” (System). The accounts were then assigned to a domain matching local operation and were delegated new privileges.

T1136.002
Domain Account
GroupBlackByte

BlackByte created privileged domain accounts during intrusions.

T1136.002
Domain Account
GroupGALLIUM

GALLIUM created high-privileged domain user accounts to maintain access to victim networks.

T1136.002
Domain Account
GroupHAFNIUM

HAFNIUM has created domain accounts.

T1136.002
Domain Account
GroupMedusa Group

Medusa Group has created a domain account within the victim environment.

T1136.002
Domain Account
GroupWizard Spider

Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence.

T1136.002
Domain Account
ToolNet

The net user username \password \domain commands in Net can be used to create a domain account.

T1136.002
Domain Account
ToolEmpire

Empire has a module for creating a new domain user if permissions allow.

T1136.002
Domain Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create domain accounts.

T1136.002
Domain Account
ToolPsExec

PsExec has the ability to remotely create accounts on target systems.

T1136.003
Cloud Account
GroupAPT29

APT29 can create new users through Azure AD.

T1136.003
Cloud Account
GroupLAPSUS$

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.

T1136.003
Cloud Account
ToolAADInternals

AADInternals can create new Azure AD users.

T1137
Office Application Startup
GroupAPT32

APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence.

T1137
Office Application Startup
GroupGamaredon Group

Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the /altvba option, once the Application.Startup event is received.

T1137.001
Office Template Macros
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT.

T1137.001
Office Template Macros
GroupMuddyWater

MuddyWater has used a Word Template, Normal.dotm, for persistence.

T1137.001
Office Template Macros
MalwareROAMINGHOUSE

ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro.

T1137.001
Office Template Macros
MalwareCobalt Strike

Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission.

T1137.001
Office Template Macros
MalwareBackConfig

BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros.

T1137.002
Office Test
GroupAPT28

APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key HKCU\Software\Microsoft\Office test\Special\Perf to execute code.

T1137.003
Outlook Forms
ToolRuler

Ruler can be used to automate the abuse of Outlook Forms to establish persistence.

T1137.004
Outlook Home Page
GroupOilRig

OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse.

T1137.004
Outlook Home Page
ToolRuler

Ruler can be used to automate the abuse of Outlook Home Pages to establish persistence.

T1137.005
Outlook Rules
ToolRuler

Ruler can be used to automate the abuse of Outlook Rules to establish persistence.

T1137.006
Add-ins
GroupNaikon

Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.