Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
CampaignC0018 | During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network. |
| T1021.001 Remote Desktop Protocol |
CampaignC0018 | During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892. |
| T1027.010 Command Obfuscation |
CampaignC0018 | During C0018, the threat actors used Base64 to encode their PowerShell scripts. |
| T1033 System Owner/User Discovery |
CampaignC0018 | During C0018, the threat actors collected `whoami` information via PowerShell scripts. |
| T1036 Masquerading |
CampaignC0018 | During C0018, AvosLocker was disguised using the victim company name as the filename. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| T1046 Network Service Discovery |
CampaignC0018 | During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning. |
| T1047 Windows Management Instrumentation |
CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| T1059.001 PowerShell |
CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| T1071.001 Web Protocols |
CampaignC0018 | During C0018, the threat actors used HTTP for C2 communications. |
| T1072 Software Deployment Tools |
CampaignC0018 | During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network. |
| T1105 Ingress Tool Transfer |
CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| T1190 Exploit Public-Facing Application |
CampaignC0018 | During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. |
| T1218.011 Rundll32 |
CampaignC0018 | During C0018, the threat actors used `rundll32` to run Mimikatz. |
| T1219.002 Remote Desktop Software |
CampaignC0018 | During C0018, the threat actors used AnyDesk to transfer tools between systems. |
| T1486 Data Encrypted for Impact |
CampaignC0018 | During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network. |
| T1570 Lateral Tool Transfer |
CampaignC0018 | During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy. |
| T1571 Non-Standard Port |
CampaignC0018 | During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections. |
| T1588.002 Tool |
CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.