Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1482 Domain Trust Discovery |
GroupStorm-0501 | Storm-0501 has used Windows native utility Nltest `nltest.exe` for discovery. |
| T1482 Domain Trust Discovery |
GroupLotus Blossom | Lotus Blossom has used tools such as AdFind to make Active Directory queries. |
| T1482 Domain Trust Discovery |
GroupChimera | Chimera has |
| T1482 Domain Trust Discovery |
GroupMirrorFace | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships. |
| T1482 Domain Trust Discovery |
GroupEarth Lusca | Earth Lusca has used Nltest to obtain information about domain controllers. |
| T1482 Domain Trust Discovery |
GroupMagic Hound | Magic Hound has used a web shell to execute `nltest /trusted_domains` to identify trust relationships. |
| T1482 Domain Trust Discovery |
GroupFIN8 | FIN8 has retrieved a list of trusted domains by using |
| T1484.001 Group Policy Modification |
GroupIndrik Spider | Indrik Spider has used Group Policy Objects to deploy batch scripts. |
| T1484.001 Group Policy Modification |
GroupAPT41 | APT41 used scheduled tasks created via Group Policy Objects (GPOs) to deploy ransomware. |
| T1484.001 Group Policy Modification |
GroupStorm-0501 | Storm-0501 distributed Group Policy Objects to tamper with security products. |
| T1484.001 Group Policy Modification |
GroupCinnamon Tempest | Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment. |
| T1484.001 Group Policy Modification |
GroupVOID MANTICORE | VOID MANTICORE had utilized Group Policy logon scripts to distribute the malicious payloads to victim devices through the execution of a batch file. |
| T1484.002 Trust Modification |
GroupScattered Spider | Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking. |
| T1484.002 Trust Modification |
GroupStorm-0501 | Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use. |
| T1485 Data Destruction |
GroupAPT38 | APT38 has used a custom secure delete function to make deleted files unrecoverable. |
| T1485 Data Destruction |
GroupSandworm Team | Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes. |
| T1485 Data Destruction |
GroupStorm-0501 | Storm-0501 has destroyed data and backup files. |
| T1485 Data Destruction |
GroupLazarus Group | Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory. |
| T1485 Data Destruction |
GroupLAPSUS$ | LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud. |
| T1485 Data Destruction |
GroupVOID MANTICORE | VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them. |
| T1485 Data Destruction |
GroupTeamPCP | TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts. |
| T1485 Data Destruction |
GroupShinyHunters | ShinyHunters has executed the `DeleteBucket` API call to delete buckets. |
| T1486 Data Encrypted for Impact |
GroupAPT38 | APT38 has used Hermes ransomware to encrypt files with AES256. |
| T1486 Data Encrypted for Impact |
GroupIndrik Spider | Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1486 Data Encrypted for Impact |
GroupAPT41 | APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers. |
| T1486 Data Encrypted for Impact |
GroupStorm-1811 | Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1486 Data Encrypted for Impact |
GroupSandworm Team | Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1486 Data Encrypted for Impact |
GroupAkira | Akira encrypts files in victim environments as part of ransomware operations. |
| T1486 Data Encrypted for Impact |
GroupStorm-0501 | Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware. |
| T1486 Data Encrypted for Impact |
GroupTA505 | TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment. |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
GroupWater Galura | Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
GroupMoonstone Sleet | Moonstone Sleet has deployed ransomware in victim environments. |
| T1486 Data Encrypted for Impact |
GroupVOID MANTICORE | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts. |
| T1486 Data Encrypted for Impact |
GroupMagic Hound | Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations. |
| T1486 Data Encrypted for Impact |
GroupFIN8 | FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks. |
| T1486 Data Encrypted for Impact |
GroupTeamPCP | TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums. |
| T1489 Service Stop |
GroupIndrik Spider | Indrik Spider has used PsExec to stop services prior to the execution of ransomware. |
| T1489 Service Stop |
GroupKimsuky | Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox. |
| T1489 Service Stop |
GroupSandworm Team | Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files. |
| T1489 Service Stop |
GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| T1489 Service Stop |
GroupLazarus Group | Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users. |
| T1489 Service Stop |
GroupLAPSUS$ | LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure. |
| T1489 Service Stop |
GroupWizard Spider | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption. |
| T1490 Inhibit System Recovery |
GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| T1490 Inhibit System Recovery |
GroupSandworm Team | Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.