ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

1146 examples

TechniqueUsed byProcedure example
T1021.007
Cloud Services
CampaignC0027

During C0027, Scattered Spider used compromised Azure credentials for credential theft activity and lateral movement to on-premises systems.

T1027
Obfuscated Files or Information
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus payloads use AES-256 GCM cipher to encrypt data to include ICONICSTEALER and VEILEDSIGNAL.

T1027
Obfuscated Files or Information
CampaignC0015

During C0015, the threat actors used Base64-encoded strings.

T1027
Obfuscated Files or Information
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor.

T1027
Obfuscated Files or Information
CampaignC0017

During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.002
Software Packing
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors UPX-packed malicous payloads including 4L4MD4R ransomware.

T1027.002
Software Packing
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

T1027.002
Software Packing
CampaignOperation Spalax

For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables.

T1027.002
Software Packing
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used UPX to pack a copy of Mimikatz.

T1027.002
Software Packing
CampaignNight Dragon

During Night Dragon, threat actors used software packing in its tools.

T1027.002
Software Packing
CampaignC0017

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

T1027.003
Steganography
CampaignOperation Spalax

For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data.

T1027.003
Steganography
CampaignOperation Ghost

During Operation Ghost, APT29 used steganography to hide payloads inside valid images.

T1027.005
Indicator Removal from Tools
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates.

T1027.005
Indicator Removal from Tools
CampaignOperation Wocao

During Operation Wocao, threat actors edited variable names within the Impacket suite to avoid automated detection.

T1027.009
Embedded Payloads
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus uses embedded .dll as apart of a chained delivery mechanism to invoke the COM class factory.

T1027.009
Embedded Payloads
CampaignC0021

For C0021, the threat actors embedded a base64-encoded payload within a LNK file.

T1027.010
Command Obfuscation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed Base64-encoded PowerShell commands.

T1027.010
Command Obfuscation
CampaignFrankenstein

During Frankenstein, the threat actors ran encoded commands from the command line.

T1027.010
Command Obfuscation
CampaignC0018

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

T1027.010
Command Obfuscation
CampaignC0021

During C0021, the threat actors used encoded PowerShell commands.

T1027.010
Command Obfuscation
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors executed an encoded VBScript file.

T1027.010
Command Obfuscation
CampaignOperation Wocao

During Operation Wocao, threat actors executed PowerShell commands which were encoded or compressed using Base64, zlib, and XOR.

T1027.011
Fileless Storage
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs.

T1027.011
Fileless Storage
CampaignQuad7 Activity

Quad7 Activity has infected victim network devices by storing artifacts in the /tmp directory which is volatile in memory and will clear its contents upon shutdown or restart.

T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1027.013
Encrypted/Encoded File
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda stored installation payloads as encrypted files in hidden folders during RedDelta Modified PlugX Infection Chain Operations.

T1027.013
Encrypted/Encoded File
CampaignRedPenguin

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1027.013
Encrypted/Encoded File
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used Base64 to encode files with a custom key.

T1027.013
Encrypted/Encoded File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

T1027.013
Encrypted/Encoded File
CampaignOperation Spalax

For Operation Spalax, the threat actors used XOR-encrypted payloads.

T1027.013
Encrypted/Encoded File
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`.

T1027.013
Encrypted/Encoded File
CampaignCutting Edge

During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary.

T1027.013
Encrypted/Encoded File
CampaignShadowRay

During ShadowRay, threat actors used Base64-encrypted Python code to evade detection.

T1027.013
Encrypted/Encoded File
CampaignOuter Space

During Outer Space, OilRig deployed VBS droppers with obfuscated strings.

T1027.013
Encrypted/Encoded File
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis.

T1027.013
Encrypted/Encoded File
CampaignAPT41 DUST

APT41 DUST used encrypted payloads decrypted and executed in memory.

T1027.013
Encrypted/Encoded File
CampaignNight Dragon

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.

T1030
Data Transfer Size Limits
CampaignC0015

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

T1030
Data Transfer Size Limits
CampaignC0026

During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.

T1033
System Owner/User Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels.

T1033
System Owner/User Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.

T1033
System Owner/User Discovery
CampaignC0018

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

T1033
System Owner/User Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information.

T1033
System Owner/User Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance.

T1033
System Owner/User Discovery
CampaignNight Dragon

During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.

T1033
System Owner/User Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system.

T1033
System Owner/User Discovery
CampaignC0017

During C0017, APT41 used `whoami` to gather information from victim machines.

T1036
Masquerading
CampaignKV Botnet Activity

KV Botnet Activity involves changing process filename to pr_set_mm_exe_file and process name to pr_set_name during later infection stages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.