ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1135
Network Share Discovery
GroupTonto Team

Tonto Team has used tools such as NBTscan to enumerate network shares.

T1135
Network Share Discovery
GroupINC Ransom

INC Ransom has used Internet Explorer to view folders on other systems.

T1135
Network Share Discovery
GroupSowbug

Sowbug listed remote shared drives that were accessible from a victim.

T1135
Network Share Discovery
GroupWizard Spider

Wizard Spider has used the “net view” command to locate mapped network shares.

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

T1136
Create Account
GroupIndrik Spider

Indrik Spider used wmic.exe to add a new user to the system.

T1136
Create Account
GroupSalt Typhoon

Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`.

T1136
Create Account
GroupScattered Spider

Scattered Spider creates new user identities within the compromised organization.

T1136.001
Local Account
GroupIndrik Spider

Indrik Spider has created local system accounts and has added the accounts to privileged groups.

T1136.001
Local Account
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1136.001
Local Account
GroupKimsuky

Kimsuky has created accounts with net user.

T1136.001
Local Account
GroupAPT41

APT41 has created user accounts.

T1136.001
Local Account
GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

T1136.001
Local Account
GroupLeafminer

Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine.

T1136.001
Local Account
GroupTeamTNT

TeamTNT has created local privileged users on victim machines.

T1136.001
Local Account
GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

T1136.001
Local Account
GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

T1136.001
Local Account
GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

T1136.001
Local Account
GroupWizard Spider

Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.

T1136.001
Local Account
GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

T1136.001
Local Account
GroupMagic Hound

Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines.

T1136.001
Local Account
GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

T1136.002
Domain Account
GroupBlackByte

BlackByte created privileged domain accounts during intrusions.

T1136.002
Domain Account
GroupGALLIUM

GALLIUM created high-privileged domain user accounts to maintain access to victim networks.

T1136.002
Domain Account
GroupHAFNIUM

HAFNIUM has created domain accounts.

T1136.002
Domain Account
GroupMedusa Group

Medusa Group has created a domain account within the victim environment.

T1136.002
Domain Account
GroupWizard Spider

Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence.

T1136.003
Cloud Account
GroupAPT29

APT29 can create new users through Azure AD.

T1136.003
Cloud Account
GroupLAPSUS$

LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence.

T1137
Office Application Startup
GroupAPT32

APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence.

T1137
Office Application Startup
GroupGamaredon Group

Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the /altvba option, once the Application.Startup event is received.

T1137.001
Office Template Macros
GroupMuddyWater

MuddyWater has used a Word Template, Normal.dotm, for persistence.

T1137.002
Office Test
GroupAPT28

APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key HKCU\Software\Microsoft\Office test\Special\Perf to execute code.

T1137.004
Outlook Home Page
GroupOilRig

OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse.

T1137.006
Add-ins
GroupNaikon

Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host.

T1140
Deobfuscate/Decode Files or Information
GroupAPT38

APT38 has used the RC4 algorithm to decrypt configuration data.

T1140
Deobfuscate/Decode Files or Information
GroupBlackByte

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender.

T1140
Deobfuscate/Decode Files or Information
GroupKimsuky

Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure.

T1140
Deobfuscate/Decode Files or Information
GroupVolt Typhoon

Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil.

T1140
Deobfuscate/Decode Files or Information
GroupGorgon Group

Gorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file.

T1140
Deobfuscate/Decode Files or Information
GroupmenuPass

menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used certutil -decode to decode files on the victim’s machine when dropping UPPERCUT.

T1140
Deobfuscate/Decode Files or Information
GroupMuddyWater

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.

T1140
Deobfuscate/Decode Files or Information
GroupGamaredon Group

Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications.

T1140
Deobfuscate/Decode Files or Information
GroupStorm-1811

Storm-1811 has distributed password-protected archives such as ZIP files during intrusions.

T1140
Deobfuscate/Decode Files or Information
GroupTeamTNT

TeamTNT has used a script that decodes a Base64-encoded version of WeaveWorks Scope.

T1140
Deobfuscate/Decode Files or Information
GroupFIN7

FIN7 has decoded a malicious PowerShell script using `certutil -decode hex` and has decoded an XOR-obfuscated block of data with the key `qawsed1q2w3e`, which led to the installation of Lizar.

T1140
Deobfuscate/Decode Files or Information
GroupSandworm Team

Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip.

T1140
Deobfuscate/Decode Files or Information
GroupMustang Panda

Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads.

T1140
Deobfuscate/Decode Files or Information
GroupZIRCONIUM

ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code.

T1140
Deobfuscate/Decode Files or Information
GroupRocke

Rocke has extracted tar.gz files after downloading them from a C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.