Real-world descriptions of how a group, tool or campaign used a technique.
78 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT32 | APT32 used GetPassword_x64 to harvest credentials. |
| T1003.001 LSASS Memory |
GroupAPT32 | APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1012 Query Registry |
GroupAPT32 | APT32's backdoor can query the Windows Registry to gather system information. |
| T1016 System Network Configuration Discovery |
GroupAPT32 | APT32 used the |
| T1018 Remote System Discovery |
GroupAPT32 | APT32 has enumerated DC servers using the command |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT32 | APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| T1027.010 Command Obfuscation |
GroupAPT32 | APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.011 Fileless Storage |
GroupAPT32 | APT32's backdoor has stored its configuration in a registry key. |
| T1027.013 Encrypted/Encoded File |
GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.016 Junk Code Insertion |
GroupAPT32 | APT32 includes garbage code to mislead anti-malware software and researchers. |
| T1033 System Owner/User Discovery |
GroupAPT32 | APT32 collected the victim's username and executed the |
| T1036 Masquerading |
GroupAPT32 | APT32 has disguised a Cobalt Strike beacon as a Flash Installer. |
| T1036.003 Rename Legitimate Utilities |
GroupAPT32 | APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection. |
| T1036.004 Masquerade Task or Service |
GroupAPT32 | APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT32 | APT32's backdoor has exfiltrated data using the already opened channel with its C&C server. |
| T1046 Network Service Discovery |
GroupAPT32 | APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities. |
| T1047 Windows Management Instrumentation |
GroupAPT32 | APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT32 | APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. |
| T1049 System Network Connections Discovery |
GroupAPT32 | APT32 used the |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
| T1055 Process Injection |
GroupAPT32 | APT32 malware has injected a Cobalt Strike beacon into Rundll32.exe. |
| T1056.001 Keylogging |
GroupAPT32 | APT32 has abused the PasswordChangeNotify to monitor for and capture account password changes. |
| T1059 Command and Scripting Interpreter |
GroupAPT32 | APT32 has used COM scriptlets to download Cobalt Strike beacons. |
| T1059.001 PowerShell |
GroupAPT32 | APT32 has used PowerShell-based tools, PowerShell one-liners, and shellcode loaders for execution. |
| T1059.003 Windows Command Shell |
GroupAPT32 | APT32 has used cmd.exe for execution. |
| T1059.005 Visual Basic |
GroupAPT32 | APT32 has used macros, COM scriptlets, and VBS scripts. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT32 | APT32 has used CVE-2016-7255 to escalate privileges. |
| T1070.004 File Deletion |
GroupAPT32 | APT32's macOS backdoor can receive a “delete” command. |
| T1070.006 Timestomp |
GroupAPT32 | APT32 has used scheduled task raw XML with a backdated timestamp of June 2, 2016. The group has also set the creation time of the files dropped by the second stage of the exploit to match the creation time of kernel32.dll. Additionally, APT32 has used a random value to modify the timestamp of the file storing the clientID. |
| T1071.001 Web Protocols |
GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| T1071.003 Mail Protocols |
GroupAPT32 | APT32 has used email for C2 via an Office macro. |
| T1072 Software Deployment Tools |
GroupAPT32 | APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task. |
| T1078.003 Local Accounts |
GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| T1082 System Information Discovery |
GroupAPT32 | APT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host. |
| T1083 File and Directory Discovery |
GroupAPT32 | APT32's backdoor possesses the capability to list files and directories on a machine. |
| T1087.001 Local Account |
GroupAPT32 | APT32 enumerated administrative users using the commands |
| T1102 Web Service |
GroupAPT32 | APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1105 Ingress Tool Transfer |
GroupAPT32 | APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors. |
| T1112 Modify Registry |
GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| T1135 Network Share Discovery |
GroupAPT32 | APT32 used the |
| T1137 Office Application Startup |
GroupAPT32 | APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence. |
| T1189 Drive-by Compromise |
GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| T1203 Exploitation for Client Execution |
GroupAPT32 | APT32 has used RTF document that includes an exploit to execute malicious code. (CVE-2017-11882) |
| T1204.001 Malicious Link |
GroupAPT32 | APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1216.001 PubPrn |
GroupAPT32 | APT32 has used PubPrn.vbs within execution scripts to execute malware, possibly bypassing defenses. |
| T1218.005 Mshta |
GroupAPT32 | APT32 has used mshta.exe for code execution. |
| T1218.010 Regsvr32 |
GroupAPT32 | APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. The group has also used regsvr32 to run their backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.