ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1074.001×

28 examples

TechniqueUsed byProcedure example
T1074.001
Local Data Staging
GroupIndrik Spider

Indrik Spider has stored collected data in a .tmp file.

T1074.001
Local Data Staging
GroupGALLIUM

GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration.

T1074.001
Local Data Staging
GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1074.001
Local Data Staging
GroupPatchwork

Patchwork copied all targeted files to a directory called index that was eventually uploaded to the C&C server.

T1074.001
Local Data Staging
GroupDragonfly

Dragonfly has created a directory named "out" in the user's %AppData% folder and copied files to it.

T1074.001
Local Data Staging
GroupmenuPass

menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin.

T1074.001
Local Data Staging
GroupMuddyWater

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.

T1074.001
Local Data Staging
GroupStorm-1811

Storm-1811 has locally staged captured credentials for subsequent manual exfiltration.

T1074.001
Local Data Staging
GroupTeamTNT

TeamTNT has aggregated collected credentials in text files before exfiltrating.

T1074.001
Local Data Staging
GroupSidewinder

Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1074.001
Local Data Staging
GroupAPT39

APT39 has utilized tools to aggregate data prior to exfiltration.

T1074.001
Local Data Staging
GroupUNC3886

UNC3886 has staged captured credentials in `var/log/ldapd<unique_keyword>.2.gz`.

T1074.001
Local Data Staging
GroupLeviathan

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.001
Local Data Staging
GroupFIN5

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.

T1074.001
Local Data Staging
GroupLotus Blossom

Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration.

T1074.001
Local Data Staging
GroupChimera

Chimera has staged stolen data locally on compromised hosts.

T1074.001
Local Data Staging
GroupBackdoorDiplomacy

BackdoorDiplomacy has copied files of interest to the main drive's recycle bin.

T1074.001
Local Data Staging
GroupAgrius

Agrius has used the folder, C:\\windows\\temp\\s\\, to stage data for exfiltration.

T1074.001
Local Data Staging
GroupAPT28

APT28 has stored captured credential information in a file named pi.log.

T1074.001
Local Data Staging
GroupAPT5

APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`.

T1074.001
Local Data Staging
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server.

T1074.001
Local Data Staging
GroupWizard Spider

Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration.

T1074.001
Local Data Staging
GroupWIRTE

WIRTE has staged collected documents of interest in `C:\Users\Public folder`.

T1074.001
Local Data Staging
GroupThreat Group-3390

Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts.

T1074.001
Local Data Staging
GroupFIN13

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.