ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0649×

21 examples

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwareSMOKEDHAM

The SMOKEDHAM source code is embedded in the dropper as an encrypted string.

T1033
System Owner/User Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used whoami commands to identify system owners.

T1041
Exfiltration Over C2 Channel
MalwareSMOKEDHAM

SMOKEDHAM has exfiltrated data to its C2 server.

T1056.001
Keylogging
MalwareSMOKEDHAM

SMOKEDHAM can continuously capture keystrokes.

T1059.001
PowerShell
MalwareSMOKEDHAM

SMOKEDHAM can execute Powershell commands sent from its C2 server.

T1071.001
Web Protocols
MalwareSMOKEDHAM

SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests.

T1082
System Information Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used the systeminfo command on a compromised host.

T1087.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has used net.exe user and net.exe users to enumerate local accounts on a compromised host.

T1090.004
Domain Fronting
MalwareSMOKEDHAM

SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain.

T1098.007
Additional Local or Domain Groups
MalwareSMOKEDHAM

SMOKEDHAM has added user accounts to local Admin groups.

T1102
Web Service
MalwareSMOKEDHAM

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1105
Ingress Tool Transfer
MalwareSMOKEDHAM

SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.

T1112
Modify Registry
MalwareSMOKEDHAM

SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.

T1113
Screen Capture
MalwareSMOKEDHAM

SMOKEDHAM can capture screenshots of the victim’s desktop.

T1132.001
Standard Encoding
MalwareSMOKEDHAM

SMOKEDHAM has encoded its C2 traffic with Base64.

T1136.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has created user accounts.

T1204.001
Malicious Link
MalwareSMOKEDHAM

SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing.

T1547.001
Registry Run Keys / Startup Folder
MalwareSMOKEDHAM

SMOKEDHAM has used reg.exe to create a Registry Run key.

T1564.002
Hidden Users
MalwareSMOKEDHAM

SMOKEDHAM has modified the Registry to hide created user accounts from the Windows logon screen.

T1573.001
Symmetric Cryptography
MalwareSMOKEDHAM

SMOKEDHAM has encrypted its C2 traffic with RC4.

T1598.003
Spearphishing Link
MalwareSMOKEDHAM

SMOKEDHAM has been delivered via malicious links in phishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.