ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1210×

13 examples

TechniqueUsed byProcedure example
T1210
Exploitation of Remote Services
MalwareTrickBot

TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll.

T1210
Exploitation of Remote Services
MalwareStuxnet

Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities.

T1210
Exploitation of Remote Services
MalwareBad Rabbit

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

T1210
Exploitation of Remote Services
MalwareEmotet

Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.

T1210
Exploitation of Remote Services
MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

T1210
Exploitation of Remote Services
MalwareLucifer

Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144).

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1210
Exploitation of Remote Services
MalwareConficker

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

T1210
Exploitation of Remote Services
MalwareWannaCry

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1210
Exploitation of Remote Services
MalwareQakBot

QakBot can move laterally using worm-like functionality through exploitation of SMB.

T1210
Exploitation of Remote Services
ToolEmpire

Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers.

T1210
Exploitation of Remote Services
ToolPoshC2

PoshC2 contains a module for exploiting SMB via EternalBlue.

T1210
Exploitation of Remote Services
MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.