Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers, including CyaX, to obfuscate malicious executables. |
| T1027.003 Steganography |
CampaignOperation Spalax | For Operation Spalax, the threat actors used packers that read pixel data from images contained in PE files' resource sections and build the next layer of execution from the data. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Spalax | For Operation Spalax, the threat actors used XOR-encrypted payloads. |
| T1059 Command and Scripting Interpreter |
CampaignOperation Spalax | For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware. |
| T1102 Web Service |
CampaignOperation Spalax | During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Spalax | For Operation Spalax, the threat actors used a variety of packers and droppers to decrypt malicious payloads. |
| T1204.001 Malicious Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to click on a malicious link distributed via phishing emails. |
| T1204.002 Malicious File |
CampaignOperation Spalax | During Operation Spalax, the threat actors relied on a victim to open a PDF document and click on an embedded malicious link to download malware. |
| T1218.011 Rundll32 |
CampaignOperation Spalax | During Operation Spalax, the threat actors used `rundll32.exe` to execute malicious installers. |
| T1497 Virtualization/Sandbox Evasion |
CampaignOperation Spalax | During Operation Spalax, the threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails that included a PDF document that in some cases led to the download and execution of malware. |
| T1566.002 Spearphishing Link |
CampaignOperation Spalax | During Operation Spalax, the threat actors sent phishing emails to victims that contained a malicious link. |
| T1568 Dynamic Resolution |
CampaignOperation Spalax | For Operation Spalax, the threat actors used dynamic DNS services, including Duck DNS and DNS Exit, as part of their C2 infrastructure. |
| T1583.001 Domains |
CampaignOperation Spalax | For Operation Spalax, the threat actors registered hundreds of domains using Duck DNS and DNS Exit. |
| T1588.001 Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained malware, including Remcos, njRAT, and AsyncRAT. |
| T1588.002 Tool |
CampaignOperation Spalax | For Operation Spalax, the threat actors obtained packers such as CyaX. |
| T1608.001 Upload Malware |
CampaignOperation Spalax | For Operation Spalax, the threat actors staged malware and malicious files in legitimate hosting services such as OneDrive or MediaFire. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.