Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1568.002 Domain Generation Algorithms |
GroupAPT41 | APT41 has used DGAs to change their C2 servers monthly. |
| T1568.002 Domain Generation Algorithms |
GroupTA551 | TA551 has used a DGA to generate URLs from executed macros. |
| T1568.003 DNS Calculation |
GroupAPT12 | APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port. |
| T1569.002 Service Execution |
GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
| T1569.002 Service Execution |
GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| T1569.002 Service Execution |
GroupFIN7 | FIN7 has started the SSH service by executing `sc start sshd`. |
| T1569.002 Service Execution |
GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
| T1569.002 Service Execution |
GroupKe3chang | Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries. |
| T1569.002 Service Execution |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service. |
| T1569.002 Service Execution |
GroupChimera | Chimera has used PsExec to deploy beacons on compromised systems. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1569.002 Service Execution |
GroupINC Ransom | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`. |
| T1569.002 Service Execution |
GroupSilence | Silence has used Winexe to install a service on the remote system. |
| T1569.002 Service Execution |
GroupWizard Spider | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network. |
| T1569.002 Service Execution |
GroupVelvet Ant | Velvet Ant executed and installed PlugX as a Windows service. |
| T1569.002 Service Execution |
GroupMoonstone Sleet | Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services. |
| T1569.003 Systemctl |
GroupTeamTNT | TeamTNT has created system services to execute cryptocurrency mining software. |
| T1570 Lateral Tool Transfer |
GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| T1570 Lateral Tool Transfer |
GroupGALLIUM | GALLIUM has used PsExec to move laterally between hosts in the target network. |
| T1570 Lateral Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has copied web shells between servers in targeted environments. |
| T1570 Lateral Tool Transfer |
GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| T1570 Lateral Tool Transfer |
GroupAPT32 | APT32 has deployed tools after moving laterally using administrative accounts. |
| T1570 Lateral Tool Transfer |
GroupStorm-1811 | Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1570 Lateral Tool Transfer |
GroupUNC3886 | UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs. |
| T1570 Lateral Tool Transfer |
GroupAoqin Dragon | Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1570 Lateral Tool Transfer |
GroupChimera | Chimera has copied tools between compromised hosts using SMB. |
| T1570 Lateral Tool Transfer |
GroupMedusa Group | Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment. |
| T1570 Lateral Tool Transfer |
GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| T1570 Lateral Tool Transfer |
GroupAgrius | Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as |
| T1570 Lateral Tool Transfer |
GroupINC Ransom | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
GroupWizard Spider | Wizard Spider has used stolen credentials to copy tools into the |
| T1570 Lateral Tool Transfer |
GroupVelvet Ant | Velvet Ant transferred files laterally within victim networks through the Impacket toolkit. |
| T1570 Lateral Tool Transfer |
GroupMagic Hound | Magic Hound has copied tools within a compromised network using RDP. |
| T1570 Lateral Tool Transfer |
GroupFIN10 | FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally. |
| T1571 Non-Standard Port |
GroupAPT32 | An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration. |
| T1571 Non-Standard Port |
GroupMuddyWater | MuddyWater has used ports 8043 and 8848 for botnet C2 communication. |
| T1571 Non-Standard Port |
GroupRedEcho | RedEcho has used non-standard ports such as TCP 8080 for HTTP communication. |
| T1571 Non-Standard Port |
GroupGamaredon Group | Gamaredon Group has used port 6856 for C2 communications. |
| T1571 Non-Standard Port |
GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| T1571 Non-Standard Port |
GroupSandworm Team | Sandworm Team has used port 6789 to accept connections on the group's SSH server. |
| T1571 Non-Standard Port |
GroupRocke | Rocke's miner connects to a C2 server using port 51640. |
| T1571 Non-Standard Port |
GroupContagious Interview | Contagious Interview has used TCP port 1224 for C2. |
| T1571 Non-Standard Port |
GroupDarkVishnya | DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| T1571 Non-Standard Port |
GroupEmber Bear | Ember Bear has used various non-standard ports for C2 communication. |
| T1571 Non-Standard Port |
GroupAPT-C-36 | APT-C-36 has used port 4050 for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.