ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1482
Domain Trust Discovery
GroupStorm-0501

Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery.

T1482
Domain Trust Discovery
GroupLotus Blossom

Lotus Blossom has used tools such as AdFind to make Active Directory queries.

T1482
Domain Trust Discovery
GroupChimera

Chimera has nltest /domain_trusts to identify domain trust relationships.

T1482
Domain Trust Discovery
GroupMirrorFace

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.

T1482
Domain Trust Discovery
GroupEarth Lusca

Earth Lusca has used Nltest to obtain information about domain controllers.

T1482
Domain Trust Discovery
GroupMagic Hound

Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships.

T1482
Domain Trust Discovery
GroupFIN8

FIN8 has retrieved a list of trusted domains by using nltest.exe /domain_trusts.

T1484.001
Group Policy Modification
GroupIndrik Spider

Indrik Spider has used Group Policy Objects to deploy batch scripts.

T1484.001
Group Policy Modification
GroupAPT41

APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware.

T1484.001
Group Policy Modification
GroupStorm-0501

Storm-0501 distributed Group Policy Objects to tamper with security products.

T1484.001
Group Policy Modification
GroupCinnamon Tempest

Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.

T1484.001
Group Policy Modification
GroupVOID MANTICORE

VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file.

T1484.002
Trust Modification
GroupScattered Spider

Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking.

T1484.002
Trust Modification
GroupStorm-0501

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.

T1485
Data Destruction
GroupAPT38

APT38 has used a custom secure delete function to make deleted files unrecoverable.

T1485
Data Destruction
GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

T1485
Data Destruction
GroupStorm-0501

Storm-0501 has destroyed data and backup files.

T1485
Data Destruction
GroupLazarus Group

Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory.

T1485
Data Destruction
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.

T1485
Data Destruction
GroupVOID MANTICORE

VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.

T1485
Data Destruction
GroupTeamPCP

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.

T1485
Data Destruction
GroupShinyHunters

ShinyHunters has executed the `DeleteBucket` API call to delete buckets.

T1486
Data Encrypted for Impact
GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

T1486
Data Encrypted for Impact
GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1486
Data Encrypted for Impact
GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

T1486
Data Encrypted for Impact
GroupStorm-1811

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1486
Data Encrypted for Impact
GroupSandworm Team

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1486
Data Encrypted for Impact
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

T1486
Data Encrypted for Impact
GroupStorm-0501

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.

T1486
Data Encrypted for Impact
GroupTA505

TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupWater Galura

Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
GroupMoonstone Sleet

Moonstone Sleet has deployed ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupVOID MANTICORE

VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1486
Data Encrypted for Impact
GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

T1486
Data Encrypted for Impact
GroupTeamPCP

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.

T1489
Service Stop
GroupIndrik Spider

Indrik Spider has used PsExec to stop services prior to the execution of ransomware.

T1489
Service Stop
GroupKimsuky

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.

T1489
Service Stop
GroupSandworm Team

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.

T1489
Service Stop
GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

T1489
Service Stop
GroupLazarus Group

Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users.

T1489
Service Stop
GroupLAPSUS$

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.

T1489
Service Stop
GroupWizard Spider

Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.

T1490
Inhibit System Recovery
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

T1490
Inhibit System Recovery
GroupSandworm Team

Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.