ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

T1021.002
SMB/Windows Admin Shares
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally.

T1021.002
SMB/Windows Admin Shares
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares.

T1021.002
SMB/Windows Admin Shares
CampaignOperation Wocao

During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally.

T1021.002
SMB/Windows Admin Shares
CampaignLeviathan Australian Intrusions

Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1021.002
SMB/Windows Admin Shares
GroupAPT3

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupAPT41

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

T1021.002
SMB/Windows Admin Shares
GroupAPT32

APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.

T1021.002
SMB/Windows Admin Shares
GroupStorm-1811

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.

T1021.002
SMB/Windows Admin Shares
GroupSandworm Team

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.

T1021.002
SMB/Windows Admin Shares
GroupAPT39

APT39 has used SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupMoses Staff

Moses Staff has used batch scripts that can enable SMB on a compromised host.

T1021.002
SMB/Windows Admin Shares
GroupOrangeworm

Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS.

T1021.002
SMB/Windows Admin Shares
GroupAquatic Panda

Aquatic Panda used remote shares to enable lateral movement in victim environments.

T1021.002
SMB/Windows Admin Shares
GroupKe3chang

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1021.002
SMB/Windows Admin Shares
GroupBlue Mockingbird

Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.

T1021.002
SMB/Windows Admin Shares
GroupTurla

Turla used net use commands to connect to lateral systems within a network.

T1021.002
SMB/Windows Admin Shares
GroupCinnamon Tempest

Cinnamon Tempest has used SMBexec for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupChimera

Chimera has used Windows admin shares to move laterally.

T1021.002
SMB/Windows Admin Shares
GroupMirrorFace

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1021.002
SMB/Windows Admin Shares
GroupDeep Panda

Deep Panda uses net.exe to connect to network shares using net use commands with compromised credentials.

T1021.002
SMB/Windows Admin Shares
GroupToddyCat

ToddyCat has used locally mounted network shares for lateral movement through targated environments.

T1021.002
SMB/Windows Admin Shares
GroupAPT28

APT28 has mapped network drives using Net and administrator credentials.

T1021.002
SMB/Windows Admin Shares
GroupFox Kitten

Fox Kitten has used valid accounts to access SMB shares.

T1021.002
SMB/Windows Admin Shares
GroupLazarus Group

Lazarus Group malware SierraAlfa accesses the ADMIN$ share via SMB to conduct lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupThreat Group-1314

Threat Group-1314 actors mapped network drives using net use.

T1021.002
SMB/Windows Admin Shares
GroupWizard Spider

Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupVelvet Ant

Velvet Ant has transferred tools within victim environments using SMB.

T1021.002
SMB/Windows Admin Shares
GroupPlay

Play has used Cobalt Strike to move laterally via SMB.

T1021.002
SMB/Windows Admin Shares
GroupFIN8

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupFIN13

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.

T1021.002
SMB/Windows Admin Shares
MalwareStuxnet

Stuxnet propagates to available network shares.

T1021.002
SMB/Windows Admin Shares
MalwarereGeorg

reGeorg has the ability to tunnel SMB sessions.

T1021.002
SMB/Windows Admin Shares
MalwareRansomHub

RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.

T1021.002
SMB/Windows Admin Shares
MalwareEmotet

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareOlympic Destroyer

Olympic Destroyer uses PsExec to interact with the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareRegin

The Regin malware platform can use Windows admin shares to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareConti

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

T1021.002
SMB/Windows Admin Shares
MalwareDiavol

Diavol can spread throughout a network via SMB prior to encryption.

T1021.002
SMB/Windows Admin Shares
MalwareLucifer

Lucifer can infect victims by brute forcing SMB.

T1021.002
SMB/Windows Admin Shares
MalwareBlackEnergy

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

T1021.002
SMB/Windows Admin Shares
MalwarezwShell

zwShell has been copied over network shares to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareNotPetya

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareConficker

Conficker variants spread through NetBIOS share propagation.

T1021.002
SMB/Windows Admin Shares
MalwareAnchor

Anchor can support windows execution via SMB shares.

T1021.002
SMB/Windows Admin Shares
MalwareLockBit 3.0

LockBit 3.0 can use SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareRoyal

Royal can use SMB to connect to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareShamoon

Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.