ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1559.002×

11 examples

TechniqueUsed byProcedure example
T1559.002
Dynamic Data Exchange
GroupPatchwork

Patchwork leveraged the DDE protocol to deliver their malware.

T1559.002
Dynamic Data Exchange
GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

T1559.002
Dynamic Data Exchange
GroupGallmaker

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

T1559.002
Dynamic Data Exchange
GroupFIN7

FIN7 spear phishing campaigns have included malicious Word documents with DDE execution.

T1559.002
Dynamic Data Exchange
GroupSidewinder

Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.

T1559.002
Dynamic Data Exchange
GroupAPT37

APT37 has used Windows DDE for execution of commands and a malicious VBS.

T1559.002
Dynamic Data Exchange
GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

T1559.002
Dynamic Data Exchange
GroupTA505

TA505 has leveraged malicious Word documents that abused DDE.

T1559.002
Dynamic Data Exchange
GroupBITTER

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

T1559.002
Dynamic Data Exchange
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

T1559.002
Dynamic Data Exchange
GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.