ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1568.002
Domain Generation Algorithms
GroupAPT41

APT41 has used DGAs to change their C2 servers monthly.

T1568.002
Domain Generation Algorithms
GroupTA551

TA551 has used a DGA to generate URLs from executed macros.

T1568.003
DNS Calculation
GroupAPT12

APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port.

T1569.002
Service Execution
GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1569.002
Service Execution
GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

T1569.002
Service Execution
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

T1569.002
Service Execution
GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

T1569.002
Service Execution
GroupFIN7

FIN7 has started the SSH service by executing `sc start sshd`.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

T1569.002
Service Execution
GroupKe3chang

Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries.

T1569.002
Service Execution
GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.

T1569.002
Service Execution
GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

T1569.002
Service Execution
GroupMedusa Group

Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration.

T1569.002
Service Execution
GroupINC Ransom

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.

T1569.002
Service Execution
GroupSilence

Silence has used Winexe to install a service on the remote system.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1569.002
Service Execution
GroupVelvet Ant

Velvet Ant executed and installed PlugX as a Windows service.

T1569.002
Service Execution
GroupMoonstone Sleet

Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services.

T1569.003
Systemctl
GroupTeamTNT

TeamTNT has created system services to execute cryptocurrency mining software.

T1570
Lateral Tool Transfer
GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

T1570
Lateral Tool Transfer
GroupGALLIUM

GALLIUM has used PsExec to move laterally between hosts in the target network.

T1570
Lateral Tool Transfer
GroupVolt Typhoon

Volt Typhoon has copied web shells between servers in targeted environments.

T1570
Lateral Tool Transfer
GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

T1570
Lateral Tool Transfer
GroupAPT32

APT32 has deployed tools after moving laterally using administrative accounts.

T1570
Lateral Tool Transfer
GroupStorm-1811

Storm-1811 has used the Impacket toolset to move and remotely execute payloads to other hosts in victim networks.

T1570
Lateral Tool Transfer
GroupSandworm Team

Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access.

T1570
Lateral Tool Transfer
GroupUNC3886

UNC3886 has utilzed Python scripts to transfer files between ESXi hosts and guest VMs.

T1570
Lateral Tool Transfer
GroupAoqin Dragon

Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices.

T1570
Lateral Tool Transfer
GroupTurla

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.

T1570
Lateral Tool Transfer
GroupChimera

Chimera has copied tools between compromised hosts using SMB.

T1570
Lateral Tool Transfer
GroupMedusa Group

Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.

T1570
Lateral Tool Transfer
GroupEmber Bear

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.

T1570
Lateral Tool Transfer
GroupAgrius

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.

T1570
Lateral Tool Transfer
GroupINC Ransom

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
GroupWizard Spider

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.

T1570
Lateral Tool Transfer
GroupVelvet Ant

Velvet Ant transferred files laterally within victim networks through the Impacket toolkit.

T1570
Lateral Tool Transfer
GroupMagic Hound

Magic Hound has copied tools within a compromised network using RDP.

T1570
Lateral Tool Transfer
GroupFIN10

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

T1571
Non-Standard Port
GroupAPT32

An APT32 backdoor can use HTTP over a non-standard TCP port (e.g 14146) which is specified in the backdoor configuration.

T1571
Non-Standard Port
GroupMuddyWater

MuddyWater has used ports 8043 and 8848 for botnet C2 communication.

T1571
Non-Standard Port
GroupRedEcho

RedEcho has used non-standard ports such as TCP 8080 for HTTP communication.

T1571
Non-Standard Port
GroupGamaredon Group

Gamaredon Group has used port 6856 for C2 communications.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

T1571
Non-Standard Port
GroupSandworm Team

Sandworm Team has used port 6789 to accept connections on the group's SSH server.

T1571
Non-Standard Port
GroupRocke

Rocke's miner connects to a C2 server using port 51640.

T1571
Non-Standard Port
GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

T1571
Non-Standard Port
GroupDarkVishnya

DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2.

T1571
Non-Standard Port
GroupEmber Bear

Ember Bear has used various non-standard ports for C2 communication.

T1571
Non-Standard Port
GroupAPT-C-36

APT-C-36 has used port 4050 for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.