Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1210 Exploitation of Remote Services |
MalwareTrickBot | TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll. |
| T1210 Exploitation of Remote Services |
MalwareStuxnet | Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities. |
| T1210 Exploitation of Remote Services |
MalwareBad Rabbit | Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks. |
| T1210 Exploitation of Remote Services |
MalwareEmotet | Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. |
| T1210 Exploitation of Remote Services |
MalwareInvisiMole | InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively. |
| T1210 Exploitation of Remote Services |
MalwareLucifer | Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144). |
| T1210 Exploitation of Remote Services |
MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1210 Exploitation of Remote Services |
MalwareConficker | Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| T1210 Exploitation of Remote Services |
MalwareWannaCry | WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network. |
| T1210 Exploitation of Remote Services |
MalwareQakBot | QakBot can move laterally using worm-like functionality through exploitation of SMB. |
| T1210 Exploitation of Remote Services |
ToolEmpire | Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers. |
| T1210 Exploitation of Remote Services |
ToolPoshC2 | PoshC2 contains a module for exploiting SMB via EternalBlue. |
| T1210 Exploitation of Remote Services |
MalwareFlame | Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.