ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1608.002
Upload Tool
GroupMedusa Group

Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.

T1608.002
Upload Tool
GroupThreat Group-3390

Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites.

T1608.003
Install Digital Certificate
GroupSea Turtle

Sea Turtle captured legitimate SSL certificates from victim organizations and installed these on Sea Turtle-controlled infrastructure to enable subsequent adversary-in-the-middle operations.

T1608.004
Drive-by Target
CampaignC0010

For C0010, the threat actors compromised the login page of a legitimate Israeli shipping company and likely established a watering hole that collected visitor information.

T1608.004
Drive-by Target
GroupMustard Tempest

Mustard Tempest has injected malicious JavaScript into compromised websites to infect victims via drive-by download.

T1608.004
Drive-by Target
GroupDragonfly

Dragonfly has compromised websites to redirect traffic and to host exploit kits.

T1608.004
Drive-by Target
GroupAPT32

APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update.

T1608.004
Drive-by Target
GroupFIN7

FIN7 has compromised a digital product website and modified multiple download links to point to trojanized versions of offered digital products.

T1608.004
Drive-by Target
GroupCURIUM

CURIUM used strategic website compromise to fingerprint then target victims.

T1608.004
Drive-by Target
GroupLuminousMoth

LuminousMoth has redirected compromised machines to an actor-controlled webpage through HTML injection.

T1608.004
Drive-by Target
GroupTransparent Tribe

Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

T1608.004
Drive-by Target
GroupThreat Group-3390

Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest.

T1608.005
Link Target
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive.

T1608.005
Link Target
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors established an Okta phishing panel which victims were tricked into accessing from mobile phones or work computers during social engineering calls.

T1608.005
Link Target
GroupFIN7

FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable.

T1608.005
Link Target
GroupSilent Librarian

Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites.

T1608.005
Link Target
GroupLuminousMoth

LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations.

T1608.006
SEO Poisoning
GroupMustard Tempest

Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware.

T1609
Container Administration Command
GroupTeamTNT

TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers.

T1609
Container Administration Command
MalwareHildegard

Hildegard was executed through the kubelet API run command and by executing commands on running containers.

T1609
Container Administration Command
MalwareSiloscape

Siloscape can send kubectl commands to victim clusters through an IRC channel and can run kubectl locally to spread once within a victim cluster.

T1609
Container Administration Command
MalwareKinsing

Kinsing was executed with an Ubuntu container entry point that runs shell scripts.

T1609
Container Administration Command
ToolPeirates

Peirates can use `kubectl` or the Kubernetes API to run commands.

T1609
Container Administration Command
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `kubectl get secrets` to extract credentials from Kubernetes.

T1609
Container Administration Command
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.

T1609
Container Administration Command
MalwareCanisterWorm

CanisterWorm can deploy privileged DaemonSets in Kubernetes clusters for data wiping using kubectl.

T1610
Deploy Container
MalwareKinsing

Kinsing was run through a deployed Ubuntu container.

T1610
Deploy Container
GroupTeamTNT

TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges.

T1610
Deploy Container
ToolPeirates

Peirates can deploy a pod that mounts its node’s root file system, then execute a command to create a reverse shell on the node.

T1610
Deploy Container
MalwareDoki

Doki was run through a deployed container.

T1611
Escape to Host
GroupTeamTNT

TeamTNT has deployed privileged containers that mount the filesystem of victim machine.

T1611
Escape to Host
MalwareHildegard

Hildegard has used the BOtB tool that can break out of containers.

T1611
Escape to Host
MalwareDoki

Doki’s container was configured to bind the host root directory.

T1611
Escape to Host
MalwareSiloscape

Siloscape maps the host’s C drive to the container by creating a global symbolic link to the host through the calling of NtSetInformationSymbolicLink.

T1611
Escape to Host
ToolPeirates

Peirates can gain a reverse shell on a host node by mounting the Kubernetes hostPath.

T1613
Container and Resource Discovery
GroupTeamTNT

TeamTNT has checked for running containers with docker ps and for specific container names with docker inspect. TeamTNT has also searched for Kubernetes pods running in a local network.

T1613
Container and Resource Discovery
MalwareHildegard

Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers.

T1613
Container and Resource Discovery
ToolPeirates

Peirates can enumerate Kubernetes pods in a given namespace.

T1613
Container and Resource Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify Docker and Kubernetes environments for credentials.

T1613
Container and Resource Discovery
MalwareCanisterWorm

CanisterWorm has performed environment fingerprinting to identify Kubernetes clusters. CanisterWorm has also searched for Kubernetes pods using the command ` os.path.exists("/var/run/secrets/kubernetes.io/serviceaccount") or "KUBERNETES_SERVICE_HOST" in os.environ `.

T1614
System Location Discovery
GroupSideCopy

SideCopy has identified the country location of a compromised host.

T1614
System Location Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system current location.

T1614
System Location Discovery
MalwareAmadey

Amadey does not run any tasks or install additional malware if the victim machine is based in Russia.

T1614
System Location Discovery
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine.

T1614
System Location Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the internal IP address, IP geolocation information of the infected host and sends the data to a C2 server. InvisibleFerret has also leveraged the “pay” module to obtain region name, country, city, zip code, ISP, latitude and longitude using “http://ip-api.com/json”.

T1614
System Location Discovery
MalwareCrimson

Crimson can identify the geographical location of a victim host.

T1614
System Location Discovery
MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

T1614
System Location Discovery
MalwareHexEval Loader

HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions.

T1614
System Location Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can determine the geographical location of a victim host by checking the language.

T1614
System Location Discovery
MalwareSameCoin

SameCoin can attempt to connect to the Israel Home Front Command site, oref.org[.]il, which is only reachable from within Israel to verify the target's location.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.