Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz. |
| T1003.002 Security Account Manager |
FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine. |
| T1003.003 NTDS |
FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it. |
| T1005 Data from Local System |
FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration. |
| T1016 System Network Configuration Discovery |
FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information. |
| T1016.001 Internet Connection Discovery |
FIN13 has used `Ping` and `tracert` for network reconnaissance efforts. |
| T1021.001 Remote Desktop Protocol |
FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers. |
| T1021.004 SSH |
FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement. |
| T1021.006 Windows Remote Management |
FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers. |
| T1036 Masquerading |
FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file. |
| T1036.004 Masquerade Task or Service |
FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory. |
| T1036.005 Match Legitimate Resource Name or Location |
FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war. |
| T1046 Network Service Discovery |
FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network. |
| T1047 Windows Management Instrumentation |
FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.