ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1021.005
VNC
GroupGamaredon Group

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

T1021.005
VNC
GroupFIN7

FIN7 has used TightVNC to control compromised hosts.

T1021.005
VNC
GroupFox Kitten

Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.

T1021.006
Windows Remote Management
GroupStorm-0501

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.

T1021.006
Windows Remote Management
GroupChimera

Chimera has used WinRM for lateral movement.

T1021.006
Windows Remote Management
GroupWizard Spider

Wizard Spider has used Window Remote Management to move laterally through a victim network.

T1021.006
Windows Remote Management
GroupThreat Group-3390

Threat Group-3390 has used WinRM to enable remote execution.

T1021.006
Windows Remote Management
GroupFIN13

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.

T1021.007
Cloud Services
GroupScattered Spider

Scattered Spider has also leveraged pre-existing AWS EC2 instances for lateral movement and data collection purposes.

T1021.007
Cloud Services
GroupStorm-0501

Storm-0501 has used compromised Entra Connect Sync Server to move laterally within the victim environment.

T1021.007
Cloud Services
GroupAPT29

APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell.

T1025
Data from Removable Media
GroupGamaredon Group

A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives.

T1025
Data from Removable Media
GroupOilRig

OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic.

T1025
Data from Removable Media
GroupTurla

Turla RPC backdoors can collect files from USB thumb drives.

T1025
Data from Removable Media
GroupAPT28

An APT28 backdoor may collect the entire contents of an inserted USB device.

T1027
Obfuscated Files or Information
GroupGALLIUM

GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection.

T1027
Obfuscated Files or Information
GroupAPT3

APT3 obfuscates files or information to help evade defensive measures.

T1027
Obfuscated Files or Information
GroupKimsuky

Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis.

T1027
Obfuscated Files or Information
GroupAPT41

APT41 used VMProtected binaries in multiple intrusions.

T1027
Obfuscated Files or Information
GroupGamaredon Group

Gamaredon Group has delivered self-extracting 7z archive files within malicious document attachments. Additionally, Gamaredon Group has used an obfuscated .drv file.

T1027
Obfuscated Files or Information
GroupGallmaker

Gallmaker obfuscated shellcode used during execution.

T1027
Obfuscated Files or Information
GroupSandworm Team

Sandworm Team has used Base64 encoding within malware variants.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027
Obfuscated Files or Information
GroupRocke

Rocke has modified UPX headers after packing files to break unpackers.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027
Obfuscated Files or Information
GroupKe3chang

Ke3chang has used Base64-encoded shellcode strings.

T1027
Obfuscated Files or Information
GroupRedCurl

RedCurl has used malware with string encryption. RedCurl has also encrypted data and has encoded PowerShell commands using Base64. RedCurl has used `PyArmor` to obfuscate code execution of LaZagne. Additionally, RedCurl has obfuscated downloaded files by renaming them as commonly used tools and has used `echo`, instead of file names themselves, to execute files.

T1027
Obfuscated Files or Information
GroupBackdoorDiplomacy

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

T1027
Obfuscated Files or Information
GroupWindshift

Windshift has used string encoding with floating point calculations.

T1027
Obfuscated Files or Information
GroupAPT-C-36

APT-C-36 has used ConfuserEx to obfuscate its variant of Imminent Monitor, compressed payloads and RAT packages, and password protected encrypted email attachments to avoid detection. APT-C-36 has also compressed initial droppers into ZIP, LHA and UUE formats.

T1027
Obfuscated Files or Information
GroupEarth Lusca

Earth Lusca used Base64 to encode strings.

T1027
Obfuscated Files or Information
GroupBlackOasis

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

T1027
Obfuscated Files or Information
GroupMoonstone Sleet

Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation.

T1027.001
Binary Padding
GroupKimsuky

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.

T1027.001
Binary Padding
GroupPatchwork

Patchwork apparently altered NDiskMonitor samples by adding four bytes of random letters in a likely attempt to change the file hashes.

T1027.001
Binary Padding
GroupMoafee

Moafee has been known to employ binary padding.

T1027.001
Binary Padding
GroupAkira

Akira has used binary padding to obfuscate payloads.

T1027.001
Binary Padding
GroupHigaisa

Higaisa performed padding with null bytes before calculating its hash.

T1027.001
Binary Padding
GroupLeviathan

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

T1027.001
Binary Padding
GroupAPT29

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

T1027.001
Binary Padding
GroupBRONZE BUTLER

BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection.

T1027.002
Software Packing
GroupAPT38

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1027.002
Software Packing
GroupElderwood

Elderwood has packed malware payloads before delivery to victims.

T1027.002
Software Packing
GroupGALLIUM

GALLIUM packed some payloads using different types of packers, both known and custom.

T1027.002
Software Packing
GroupAPT3

APT3 has been known to pack their tools.

T1027.002
Software Packing
GroupKimsuky

Kimsuky has packed malware with UPX.

T1027.002
Software Packing
GroupVolt Typhoon

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1027.002
Software Packing
GroupPatchwork

A Patchwork payload was packed with UPX.

T1027.002
Software Packing
GroupAPT41

APT41 uses packers such as Themida to obfuscate malicious files.

T1027.002
Software Packing
GroupTeamTNT

TeamTNT has used UPX and Ezuri packer to pack its binaries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.