ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1526
Cloud Service Discovery
GroupStorm-0501

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.

T1528
Steal Application Access Token
GroupAPT29

APT29 uses stolen tokens to access victim accounts, without needing a password.

T1528
Steal Application Access Token
GroupAPT28

APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection".

T1528
Steal Application Access Token
GroupTeamPCP

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.

T1528
Steal Application Access Token
GroupShinyHunters

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.

T1529
System Shutdown/Reboot
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR.

T1529
System Shutdown/Reboot
GroupAPT37

APT37 has used malware that will issue the command shutdown /r /t 1 to reboot a system after wiping its MBR.

T1529
System Shutdown/Reboot
GroupMedusa Group

Medusa Group has manually turned off and encrypted virtual machines.

T1529
System Shutdown/Reboot
GroupLazarus Group

Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems.

T1530
Data from Cloud Storage
GroupHAFNIUM

HAFNIUM has exfitrated data from OneDrive.

T1530
Data from Cloud Storage
GroupScattered Spider

Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes.

T1530
Data from Cloud Storage
GroupStorm-0501

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.

T1530
Data from Cloud Storage
GroupAPT42

APT42 has collected data from Microsoft 365 environments.

T1530
Data from Cloud Storage
GroupFox Kitten

Fox Kitten has obtained files from the victim's cloud storage instances.

T1530
Data from Cloud Storage
GroupShinyHunters

ShinyHunters has collected data from insecure cloud buckets.

T1531
Account Access Removal
GroupAkira

Akira deletes administrator accounts in victim networks prior to encryption.

T1531
Account Access Removal
GroupLAPSUS$

LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access.

T1534
Internal Spearphishing
GroupKimsuky

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.

T1534
Internal Spearphishing
GroupMuddyWater

MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails.

T1534
Internal Spearphishing
GroupGamaredon Group

Gamaredon Group has used an Outlook VBA module on infected systems to send phishing emails with malicious attachments to other employees within the organization.

T1534
Internal Spearphishing
GroupLeviathan

Leviathan has conducted internal spearphishing within the victim's environment for lateral movement.

T1534
Internal Spearphishing
GroupAPT-C-36

APT-C-36 has used a compromised account to send a phishing email to an address likely used and monitored by the IT team within the same targeted organization.

T1534
Internal Spearphishing
GroupHEXANE

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.

T1537
Transfer Data to Cloud Account
GroupStorm-0501

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.

T1537
Transfer Data to Cloud Account
GroupRedCurl

RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service.

T1537
Transfer Data to Cloud Account
GroupINC Ransom

INC Ransom has used Megasync to exfiltrate data to the cloud.

T1538
Cloud Service Dashboard
GroupScattered Spider

Scattered Spider abused AWS Systems Manager Inventory to identify targets on the compromised network prior to lateral movement.

T1539
Steal Web Session Cookie
GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

T1539
Steal Web Session Cookie
GroupEvilnum

Evilnum can steal cookies and session information from browsers.

T1539
Steal Web Session Cookie
GroupSandworm Team

Sandworm Team used information stealer malware to collect browser session cookies.

T1539
Steal Web Session Cookie
GroupScattered Spider

Scattered Spider retrieves browser cookies via Raccoon Stealer.

T1539
Steal Web Session Cookie
GroupLotus Blossom

Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome.

T1539
Steal Web Session Cookie
GroupStar Blizzard

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to
phishing domains.

T1539
Steal Web Session Cookie
GroupLuminousMoth

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

T1539
Steal Web Session Cookie
GroupAPT42

APT42 has used custom malware to steal login and cookie data from common browsers.

T1542.002
Component Firmware
GroupEquation

Equation is known to have the capability to overwrite the firmware on hard drives from some manufacturers.

T1542.003
Bootkit
GroupAPT41

APT41 deployed Master Boot Record bootkits on Windows systems to hide their malware and maintain persistence on victim systems.

T1542.003
Bootkit
GroupAPT28

APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.

T1542.003
Bootkit
GroupLazarus Group

Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down.

T1543.001
Launch Agent
GroupContagious Interview

Contagious Interview has established persistence using InvisibleFerret malware to create file to run the script on Startup via LaunchAgents. Contagious Interview has also utilized a plist file located in `/Library/LaunchAgents` to enable a malicious bash script the ability to persist.

T1543.002
Systemd Service
GroupTeamTNT

TeamTNT has established persistence through the creation of a cryptocurrency mining system service using systemctl.

T1543.002
Systemd Service
GroupRocke

Rocke has installed a systemd service script to maintain persistence.

T1543.002
Systemd Service
GroupScattered Spider

Scattered Spider has run `SYSTEMD_UNIT_PATH="/lib/systemd/
system/teleport.service` to establish persistence for the Teleport remote access tool.

T1543.002
Systemd Service
GroupTeamPCP

TeamPCP has used the systemd user service for malware persistence in targeted environments.

T1543.003
Windows Service
GroupAPT38

APT38 has installed a new Windows service to establish persistence.

T1543.003
Windows Service
GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

T1543.003
Windows Service
GroupAPT3

APT3 has a tool that creates a new service for persistence.

T1543.003
Windows Service
GroupKimsuky

Kimsuky has created new services for persistence.

T1543.003
Windows Service
GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

T1543.003
Windows Service
GroupAPT32

APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.