ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1140
Deobfuscate/Decode Files or Information
GroupAPT39

APT39 has used malware to decrypt encrypted CAB files.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1140
Deobfuscate/Decode Files or Information
GroupHigaisa

Higaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.

T1140
Deobfuscate/Decode Files or Information
GroupTropic Trooper

Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload.

T1140
Deobfuscate/Decode Files or Information
GroupKe3chang

Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them.

T1140
Deobfuscate/Decode Files or Information
GroupLeviathan

Leviathan has used a DLL known as SeDll to decrypt and execute other JavaScript backdoors.

T1140
Deobfuscate/Decode Files or Information
GroupWinter Vivern

Winter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages.

T1140
Deobfuscate/Decode Files or Information
GroupTurla

Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads.

T1140
Deobfuscate/Decode Files or Information
GroupTA505

TA505 has decrypted packed DLLs with an XOR key.

T1140
Deobfuscate/Decode Files or Information
GroupCinnamon Tempest

Cinnamon Tempest has used weaponized DLLs to load and decrypt payloads.

T1140
Deobfuscate/Decode Files or Information
GroupBRONZE BUTLER

BRONZE BUTLER downloads encoded payloads and decodes them on the victim.

T1140
Deobfuscate/Decode Files or Information
GroupDarkhotel

Darkhotel has decrypted strings and imports using RC4 during execution.

T1140
Deobfuscate/Decode Files or Information
GroupAgrius

Agrius has deployed base64-encoded variants of ASPXSpy to evade detection.

T1140
Deobfuscate/Decode Files or Information
GroupAPT28

An APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.

T1140
Deobfuscate/Decode Files or Information
GroupMalteiro

Malteiro has the ability to deobfuscate downloaded files prior to execution.

T1140
Deobfuscate/Decode Files or Information
GroupLazarus Group

Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime.

T1140
Deobfuscate/Decode Files or Information
GroupEarth Lusca

Earth Lusca has used certutil to decode a string into a cabinet file.

T1140
Deobfuscate/Decode Files or Information
GroupMolerats

Molerats decompresses ZIP files once on the victim machine.

T1140
Deobfuscate/Decode Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis.

T1140
Deobfuscate/Decode Files or Information
GroupWIRTE

WIRTE has used Base64 to decode malicious VBS script.

T1140
Deobfuscate/Decode Files or Information
GroupThreat Group-3390

During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression.

T1140
Deobfuscate/Decode Files or Information
GroupFIN13

FIN13 has utilized `certutil` to decode base64 encoded versions of custom malware.

T1140
Deobfuscate/Decode Files or Information
GroupAPT19

An APT19 HTTP malware variant decrypts strings using single-byte XOR keys.

T1176.001
Browser Extensions
GroupKimsuky

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.

T1176.002
IDE Extensions
GroupMustang Panda

Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads.

T1176.002
IDE Extensions
GroupTeamPCP

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1185
Browser Session Hijacking
GroupKimsuky

Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms.

T1187
Forced Authentication
GroupDragonfly

Dragonfly has gathered hashed user credentials over SMB using spearphishing attachments with external resource links and by modifying .LNK file icon resources to collect credentials from virtualized systems.

T1187
Forced Authentication
GroupDarkHydrus

DarkHydrus used Template Injection to launch an authentication window for users to enter their credentials.

T1189
Drive-by Compromise
GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

T1189
Drive-by Compromise
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.

T1189
Drive-by Compromise
GroupMustard Tempest

Mustard Tempest has used drive-by downloads for initial infection, often using fake browser updates as a lure.

T1189
Drive-by Compromise
GroupPatchwork

Patchwork has used watering holes to deliver files with exploits to initial victims.

T1189
Drive-by Compromise
GroupDragonfly

Dragonfly has compromised targets via strategic web compromise (SWC) utilizing a custom exploit kit.

T1189
Drive-by Compromise
GroupAPT32

APT32 has infected victims by tricking them into visiting compromised watering hole websites.

T1189
Drive-by Compromise
GroupLeafminer

Leafminer has infected victims using watering holes.

T1189
Drive-by Compromise
GroupMachete

Machete has distributed Machete through a fake blog website.

T1189
Drive-by Compromise
GroupAndariel

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

T1189
Drive-by Compromise
GroupCURIUM

CURIUM has used strategic website compromise to infect victims with malware such as IMAPLoader.

T1189
Drive-by Compromise
GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

T1189
Drive-by Compromise
GroupWindigo

Windigo has distributed Windows malware via drive-by downloads.

T1189
Drive-by Compromise
GroupLeviathan

Leviathan has infected victims using watering holes.

T1189
Drive-by Compromise
GroupWinter Vivern

Winter Vivern created dedicated web pages mimicking legitimate government websites to deliver malicious fake anti-virus software.

T1189
Drive-by Compromise
GroupTurla

Turla has infected victims using watering holes.

T1189
Drive-by Compromise
GroupDark Caracal

Dark Caracal leveraged a watering hole to serve up malicious code.

T1189
Drive-by Compromise
GroupBRONZE BUTLER

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.

T1189
Drive-by Compromise
GroupDarkhotel

Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware.

T1189
Drive-by Compromise
GroupAxiom

Axiom has used watering hole attacks to gain access.

T1189
Drive-by Compromise
GroupWindshift

Windshift has used compromised websites to register custom URL schemes on a remote system.

T1189
Drive-by Compromise
GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.