ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1098.002
Additional Email Delegate Permissions
GroupMagic Hound

Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations.

T1098.003
Additional Cloud Roles
GroupScattered Spider

Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure.

T1098.003
Additional Cloud Roles
GroupStorm-0501

Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions.

T1098.003
Additional Cloud Roles
GroupLAPSUS$

LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.

T1098.004
SSH Authorized Keys
GroupSalt Typhoon

Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices.

T1098.004
SSH Authorized Keys
GroupTeamTNT

TeamTNT has added RSA keys in authorized_keys.

T1098.004
SSH Authorized Keys
GroupEarth Lusca

Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH.

T1098.005
Device Registration
GroupAPT29

APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account.

T1098.007
Additional Local or Domain Groups
GroupAPT3

APT3 has been known to add created accounts to local admin groups to maintain elevated access.

T1098.007
Additional Local or Domain Groups
GroupKimsuky

Kimsuky has added accounts to specific groups with net localgroup.

T1098.007
Additional Local or Domain Groups
GroupAPT41

APT41 has added user accounts to the User and Admin groups.

T1098.007
Additional Local or Domain Groups
GroupDragonfly

Dragonfly has added newly created accounts to the administrators group to maintain elevated access.

T1098.007
Additional Local or Domain Groups
GroupAPT5

APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation.

T1098.007
Additional Local or Domain Groups
GroupMagic Hound

Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups.

T1098.007
Additional Local or Domain Groups
GroupFIN13

FIN13 has assigned newly created accounts the sysadmin role to maintain persistence.

T1102
Web Service
GroupEXOTIC LILY

EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads.

T1102
Web Service
GroupAPT32

APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1102
Web Service
GroupFIN6

FIN6 has used Pastebin and Google Storage to host content for their operations.

T1102
Web Service
GroupGamaredon Group

Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system.

T1102
Web Service
GroupTeamTNT

TeamTNT has leveraged iplogger.org to send collected data back to C2.

T1102
Web Service
GroupMustang Panda

Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads.

T1102
Web Service
GroupRocke

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.

T1102
Web Service
GroupTurla

Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications.

T1102
Web Service
GroupRedCurl

RedCurl has used web services to download malicious files.

T1102
Web Service
GroupLazyScripter

LazyScripter has used GitHub to host its payloads to operate spam campaigns.

T1102
Web Service
GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1102
Web Service
GroupFox Kitten

Fox Kitten has used Amazon Web Services to host C2.

T1102
Web Service
GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1102
Web Service
GroupVOID MANTICORE

VOID MANTICORE has utilized Telegram API for C2.

T1102
Web Service
GroupFIN8

FIN8 has used sslip.io, a free IP to domain mapping service that also makes SSL certificate generation easier for traffic encryption, as part of their command and control.

T1102.001
Dead Drop Resolver
GroupKimsuky

Kimsuky has used TRANSLATEXT and a dead drop resolver to retrieve configurations and commands from a public blog site.

T1102.001
Dead Drop Resolver
GroupPatchwork

Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites.

T1102.001
Dead Drop Resolver
GroupAPT41

APT41 used legitimate websites for C2 through dead drop resolvers (DDR), including GitHub, Pastebin, and Microsoft TechNet.

T1102.001
Dead Drop Resolver
GroupRocke

Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware.

T1102.001
Dead Drop Resolver
GroupBRONZE BUTLER

BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads.

T1102.001
Dead Drop Resolver
GroupRTM

RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names.

T1102.002
Bidirectional Communication
GroupKimsuky

Kimsuky has used Blogspot pages and a Github repository for C2. Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information.

T1102.002
Bidirectional Communication
GroupMuddyWater

MuddyWater has used web services including OneHub to distribute remote access tools.

T1102.002
Bidirectional Communication
GroupGamaredon Group

Gamaredon Group has used several ways to try to resolve the C2 server, including: public third-party websites, an adversary-operated Telegraph channel, the ngrok utility and the TXT record of a hardcoded C2 domain.

T1102.002
Bidirectional Communication
GroupFIN7

FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2.

T1102.002
Bidirectional Communication
GroupSandworm Team

Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com.

T1102.002
Bidirectional Communication
GroupZIRCONIUM

ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands.

T1102.002
Bidirectional Communication
GroupAPT39

APT39 has communicated with C2 through files uploaded to and downloaded from DropBox.

T1102.002
Bidirectional Communication
GroupAPT37

APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.

T1102.002
Bidirectional Communication
GroupCarbanak

Carbanak has used a VBScript named "ggldr" that uses Google Apps Script, Sheets, and Forms services for C2.

T1102.002
Bidirectional Communication
GroupPOLONIUM

POLONIUM has used OneDrive and DropBox for C2.

T1102.002
Bidirectional Communication
GroupTurla

A Turla JavaScript backdoor has used Google Apps Script as its C2 server.

T1102.002
Bidirectional Communication
GroupAPT28

APT28 has used Google Drive for C2.

T1102.002
Bidirectional Communication
GroupAPT12

APT12 has used blogs and WordPress for C2 infrastructure.

T1102.002
Bidirectional Communication
GroupLazarus Group

Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.