Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated VBScripts with randomly generated variable names and concatenated strings. |
| T1001.001 Junk Data |
GroupAPT28 | APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire. |
| T1001.002 Steganography |
GroupAxiom | Axiom has used steganography to hide its C2 communications. |
| T1001.003 Protocol or Service Impersonation |
GroupMustang Panda | Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers. |
| T1001.003 Protocol or Service Impersonation |
GroupHigaisa | Higaisa used a FakeTLS session for C2 communications. |
| T1001.003 Protocol or Service Impersonation |
GroupLazarus Group | Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption. |
| T1003 OS Credential Dumping |
GroupEmber Bear | Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003 OS Credential Dumping |
GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| T1003 OS Credential Dumping |
GroupPoseidon Group | Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers. |
| T1003 OS Credential Dumping |
GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003 OS Credential Dumping |
GroupTonto Team | Tonto Team has used a variety of credential dumping tools. |
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003 OS Credential Dumping |
GroupSuckfly | Suckfly used a signed credential-dumping tool to obtain victim account credentials. |
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003 OS Credential Dumping |
GroupSowbug | Sowbug has used credential dumping tools. |
| T1003 OS Credential Dumping |
GroupStorm-0501 | Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information. |
| T1003 OS Credential Dumping |
GroupAxiom | Axiom has been known to dump credentials. |
| T1003 OS Credential Dumping |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
| T1003.001 LSASS Memory |
GroupIndrik Spider | Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump. |
| T1003.001 LSASS Memory |
GroupGALLIUM | GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines. |
| T1003.001 LSASS Memory |
GroupAPT3 | APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1003.001 LSASS Memory |
GroupVolt Typhoon | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.001 LSASS Memory |
GroupAPT41 | APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts. |
| T1003.001 LSASS Memory |
GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1003.001 LSASS Memory |
GroupHAFNIUM | HAFNIUM has used |
| T1003.001 LSASS Memory |
GroupMuddyWater | MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1003.001 LSASS Memory |
GroupFIN6 | FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.001 LSASS Memory |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz. |
| T1003.001 LSASS Memory |
GroupSandworm Team | Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1003.001 LSASS Memory |
GroupMustang Panda | Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz. |
| T1003.001 LSASS Memory |
GroupAPT39 | APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| T1003.001 LSASS Memory |
GroupUNC3886 | UNC3886 has used MiniDump to dump process memory and search for cleartext credentials. |
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.001 LSASS Memory |
GroupAquatic Panda | Aquatic Panda has attempted to harvest credentials through LSASS memory dumping. |
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.001 LSASS Memory |
GroupAPT1 | APT1 has been known to use credential dumping using Mimikatz. |
| T1003.001 LSASS Memory |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE. |
| T1003.001 LSASS Memory |
GroupBlue Mockingbird | Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory. |
| T1003.001 LSASS Memory |
GroupRedCurl | |
| T1003.001 LSASS Memory |
GroupMirrorFace | MirrorFace has dumped LSASS memory for credential access. |
| T1003.001 LSASS Memory |
GroupCleaver | Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor. |
| T1003.001 LSASS Memory |
GroupMedusa Group | Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials. |
| T1003.001 LSASS Memory |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping. |
| T1003.001 LSASS Memory |
GroupEmber Bear | Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.001 LSASS Memory |
GroupWhitefly | |
| T1003.001 LSASS Memory |
GroupAgrius | Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1003.001 LSASS Memory |
GroupAPT5 | APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.