ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1608.004
Drive-by Target
GroupThreat Group-3390

Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest.

T1608.005
Link Target
GroupFIN7

FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable.

T1608.005
Link Target
GroupSilent Librarian

Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites.

T1608.005
Link Target
GroupLuminousMoth

LuminousMoth has created a link to a Dropbox file that has been used in their spear-phishing operations.

T1608.006
SEO Poisoning
GroupMustard Tempest

Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware.

T1609
Container Administration Command
GroupTeamTNT

TeamTNT executed Hildegard through the kubelet API run command and by executing commands on running containers.

T1610
Deploy Container
GroupTeamTNT

TeamTNT has deployed different types of containers into victim environments to facilitate execution. TeamTNT has also transferred cryptocurrency mining software to Kubernetes clusters discovered within local IP address ranges.

T1611
Escape to Host
GroupTeamTNT

TeamTNT has deployed privileged containers that mount the filesystem of victim machine.

T1613
Container and Resource Discovery
GroupTeamTNT

TeamTNT has checked for running containers with docker ps and for specific container names with docker inspect. TeamTNT has also searched for Kubernetes pods running in a local network.

T1614
System Location Discovery
GroupSideCopy

SideCopy has identified the country location of a compromised host.

T1614
System Location Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system current location.

T1614.001
System Language Discovery
GroupBlackByte

BlackByte identified system language settings to determine follow-on execution.

T1614.001
System Language Discovery
GroupKe3chang

Ke3chang has used implants to collect the system language ID of a compromised machine.

T1614.001
System Language Discovery
GroupStorm-0501

Storm-0501 has identified system language codes on a compromised host to determine if the victim falls under a non-supported language code that is prohibited for targeting, including victims associated with Russia and other Commonwealth of Independent States (CIS) that may draw attention of law enforcement in countries where the ransomware operator or affiliates may reside/operate from.

T1614.001
System Language Discovery
GroupMirrorFace

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.

T1614.001
System Language Discovery
GroupMalteiro

Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese.

T1615
Group Policy Discovery
GroupTurla

Turla surveys a system upon check-in to discover Group Policy details using the gpresult command.

T1619
Cloud Storage Object Discovery
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.

T1620
Reflective Code Loading
GroupKimsuky

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory. Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.

T1620
Reflective Code Loading
GroupGamaredon Group

Gamaredon Group has used an obfuscated PowerShell script that used `System.Reflection.Assembly` to gather and send victim information to the C2.

T1620
Reflective Code Loading
GroupFIN7

FIN7 has loaded a .NET assembly into the currect execution context via `Reflection.Assembly::Load`.

T1620
Reflective Code Loading
GroupLazarus Group

Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime.

T1621
Multi-Factor Authentication Request Generation
GroupScattered Spider

Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets.

T1621
Multi-Factor Authentication Request Generation
GroupAPT29

APT29 has used repeated MFA requests to gain access to victim accounts.

T1621
Multi-Factor Authentication Request Generation
GroupLAPSUS$

LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval.

T1622
Debugger Evasion
GroupMustang Panda

Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.

T1649
Steal or Forge Authentication Certificates
GroupAPT29

APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates.

T1650
Acquire Access
GroupMedusa Group

Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).

T1651
Cloud Administration Command
GroupAPT29

APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines.

T1651
Cloud Administration Command
GroupVOID MANTICORE

VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices.

T1652
Device Driver Discovery
GroupMedusa Group

Medusa Group has queried drivers on the victim device through the command `driverquery`.

T1654
Log Enumeration
GroupVolt Typhoon

Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.

T1654
Log Enumeration
GroupMustang Panda

Mustang Panda has used Wevtutil to gather Windows Security Event Logs.

T1654
Log Enumeration
GroupAquatic Panda

Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.

T1654
Log Enumeration
GroupEmber Bear

Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions.

T1654
Log Enumeration
GroupAPT5

APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs.

T1657
Financial Theft
GroupKimsuky

Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure.

T1657
Financial Theft
GroupAppleJeus

AppleJeus has targeted the cryptocurrency industry with the goal of stealing digital assets.

T1657
Financial Theft
GroupScattered Spider

Scattered Spider has deployed ransomware on compromised hosts and threatened to leak stolen data for financial gain.

T1657
Financial Theft
GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

T1657
Financial Theft
GroupAkira

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.

T1657
Financial Theft
GroupSilverTerrier

SilverTerrier targets organizations in high technology, higher education, and manufacturing for business email compromise (BEC) campaigns with the goal of financial theft.

T1657
Financial Theft
GroupStorm-0501

Storm-0501 has engaged in double-extortion ransomware, exfiltrating data and directly contacting victims when the primary organization refuses to pay along with posting data on their data leak sites.

T1657
Financial Theft
GroupCinnamon Tempest

Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom.

T1657
Financial Theft
GroupMedusa Group

Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.

T1657
Financial Theft
GroupWater Galura

Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site.

T1657
Financial Theft
GroupMalteiro

Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft.

T1657
Financial Theft
GroupINC Ransom

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.

T1657
Financial Theft
GroupVOID MANTICORE

VOID MANTICORE has conducted data exfiltration and posted stolen information on data leak sites for the purposes of financial and political extortion. VOID MANTICORE has also sold stolen data to prospective buyers for cryptocurrency.

T1657
Financial Theft
GroupPlay

Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.