ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1090.002
External Proxy
GroupAPT39

APT39 has used various tools to proxy C2 communications.

T1090.002
External Proxy
GroupFIN5

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.

T1090.002
External Proxy
GroupAPT29

APT29 uses compromised residential endpoints as proxies for defense evasion and network access.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1090.002
External Proxy
GroupTonto Team

Tonto Team has routed their traffic through an external server in order to obfuscate their location.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1090.002
External Proxy
GroupSilence

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

T1090.003
Multi-hop Proxy
GroupVolt Typhoon

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.

T1090.003
Multi-hop Proxy
GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

T1090.003
Multi-hop Proxy
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1090.003
Multi-hop Proxy
GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

T1090.003
Multi-hop Proxy
GroupLotus Blossom

Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1090.003
Multi-hop Proxy
GroupMedusa Group

Medusa Group has used TOR nodes for communications.

T1090.003
Multi-hop Proxy
GroupEmber Bear

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.

T1090.003
Multi-hop Proxy
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

T1090.003
Multi-hop Proxy
GroupFIN4

FIN4 has used Tor to log in to victims' email accounts.

T1090.003
Multi-hop Proxy
GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1090.003
Multi-hop Proxy
GroupShinyHunters

ShinyHunters has used Tor to host their DLS.

T1090.004
Domain Fronting
GroupAPT29

APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic.

T1091
Replication Through Removable Media
GroupGamaredon Group

Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host.

T1091
Replication Through Removable Media
GroupFIN7

FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands.

T1091
Replication Through Removable Media
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could spread through USB connections.

T1091
Replication Through Removable Media
GroupTropic Trooper

Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine.

T1091
Replication Through Removable Media
GroupAoqin Dragon

Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment.

T1091
Replication Through Removable Media
GroupDarkhotel

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

T1091
Replication Through Removable Media
GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

T1091
Replication Through Removable Media
GroupAPT28

APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted.

T1092
Communication Through Removable Media
GroupAPT28

APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted.

T1095
Non-Application Layer Protocol
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1095
Non-Application Layer Protocol
GroupHAFNIUM

HAFNIUM has used TCP for C2.

T1095
Non-Application Layer Protocol
GroupFIN6

FIN6 has used Metasploit Bind and Reverse TCP stagers.

T1095
Non-Application Layer Protocol
GroupGamaredon Group

Gamaredon Group has used SOCKS5 over port 9050 for C2 communication.

T1095
Non-Application Layer Protocol
GroupMustang Panda

Mustang Panda has utilized TCP-based reverse shells using cmd.exe.

T1095
Non-Application Layer Protocol
GroupUNC3886

UNC3886 has deployed backdoors that communicate over TCP to compromised network devices and over VMCI to ESXi hosts.

T1095
Non-Application Layer Protocol
GroupBITTER

BITTER has used TCP for C2 communications.

T1095
Non-Application Layer Protocol
GroupBackdoorDiplomacy

BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.

T1095
Non-Application Layer Protocol
GroupEmber Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.

T1095
Non-Application Layer Protocol
GroupToddyCat

ToddyCat has used a passive backdoor that receives commands with UDP packets.

T1095
Non-Application Layer Protocol
GroupMetador

Metador has used TCP for C2.

T1095
Non-Application Layer Protocol
GroupPLATINUM

PLATINUM has used the Intel® Active Management Technology (AMT) Serial-over-LAN (SOL) channel for command and control.

T1098
Account Manipulation
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

T1098
Account Manipulation
GroupScattered Spider

Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere.

T1098
Account Manipulation
GroupLazarus Group

Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account.

T1098
Account Manipulation
GroupVOID MANTICORE

VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.

T1098
Account Manipulation
GroupTeamPCP

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.

T1098.001
Additional Cloud Credentials
GroupStorm-0501

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

T1098.002
Additional Email Delegate Permissions
GroupAPT29

APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails.

T1098.002
Additional Email Delegate Permissions
GroupAPT28

APT28 has used a Powershell cmdlet to grant the ApplicationImpersonation role to a compromised account.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.