ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1550.002×

11 examples

TechniqueUsed byProcedure example
T1550.002
Pass the Hash
GroupGALLIUM

GALLIUM used dumped hashes to authenticate to other machines via pass the hash.

T1550.002
Pass the Hash
GroupKimsuky

Kimsuky has used pass the hash for authentication to remote access software used in C2.

T1550.002
Pass the Hash
GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

T1550.002
Pass the Hash
GroupAPT32

APT32 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

T1550.002
Pass the Hash
GroupAPT1

The APT1 group is known to have used pass the hash.

T1550.002
Pass the Hash
GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

T1550.002
Pass the Hash
GroupEmber Bear

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.

T1550.002
Pass the Hash
GroupAPT28

APT28 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupWizard Spider

Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.

T1550.002
Pass the Hash
GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.