Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
GroupAPT28 | APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire. |
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1003.003 NTDS |
GroupAPT28 | APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1005 Data from Local System |
GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1014 Rootkit |
GroupAPT28 | APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT28 | APT28 has mapped network drives using Net and administrator credentials. |
| T1025 Data from Removable Media |
GroupAPT28 | An APT28 backdoor may collect the entire contents of an inserted USB device. |
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1030 Data Transfer Size Limits |
GroupAPT28 | APT28 has split archived exfiltration files into chunks smaller than 1MB. |
| T1036 Masquerading |
GroupAPT28 | APT28 has renamed the WinRAR utility to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT28 | APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1037.001 Logon Script (Windows) |
GroupAPT28 | An APT28 loader Trojan adds the Registry key |
| T1039 Data from Network Shared Drive |
GroupAPT28 | APT28 has collected files from network shared drives. |
| T1040 Network Sniffing |
GroupAPT28 | APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupAPT28 | APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1057 Process Discovery |
GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1070.004 File Deletion |
GroupAPT28 | APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner. |
| T1070.006 Timestomp |
GroupAPT28 | APT28 has performed timestomping on victim files. |
| T1071.001 Web Protocols |
GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| T1071.003 Mail Protocols |
GroupAPT28 | APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims. |
| T1074.001 Local Data Staging |
GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| T1074.002 Remote Data Staging |
GroupAPT28 | APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server. |
| T1078 Valid Accounts |
GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| T1078.004 Cloud Accounts |
GroupAPT28 | APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes. |
| T1083 File and Directory Discovery |
GroupAPT28 | APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1090.003 Multi-hop Proxy |
GroupAPT28 | APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. |
| T1091 Replication Through Removable Media |
GroupAPT28 | APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted. |
| T1092 Communication Through Removable Media |
GroupAPT28 | APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT28 | APT28 has used a Powershell cmdlet to grant the |
| T1102.002 Bidirectional Communication |
GroupAPT28 | APT28 has used Google Drive for C2. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1110 Brute Force |
GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| T1110.001 Password Guessing |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks. |
| T1110.003 Password Spraying |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1119 Automated Collection |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1120 Peripheral Device Discovery |
GroupAPT28 | APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. |
| T1133 External Remote Services |
GroupAPT28 | APT28 has used Tor and a variety of commercial VPN services to route brute force authentication attempts. |
| T1134.001 Token Impersonation/Theft |
GroupAPT28 | APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation. |
| T1137.002 Office Test |
GroupAPT28 | APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT28 | An APT28 macro uses the command |
| T1189 Drive-by Compromise |
GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
| T1190 Exploit Public-Facing Application |
GroupAPT28 | APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.