ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0067×

29 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT37

APT37 has collected data from victims' local systems.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1027.003
Steganography
GroupAPT37

APT37 uses steganography to send images to users that are embedded with shellcode.

T1033
System Owner/User Discovery
GroupAPT37

APT37 identifies the victim username.

T1036.001
Invalid Code Signature
GroupAPT37

APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.”

T1053.005
Scheduled Task
GroupAPT37

APT37 has created scheduled tasks to run malicious scripts on a compromised host.

T1055
Process Injection
GroupAPT37

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

T1057
Process Discovery
GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1059
Command and Scripting Interpreter
GroupAPT37

APT37 has used Ruby scripts to execute payloads.

T1059.003
Windows Command Shell
GroupAPT37

APT37 has used the command-line interface.

T1059.005
Visual Basic
GroupAPT37

APT37 executes shellcode and a VBA script to decode Base64 strings.

T1059.006
Python
GroupAPT37

APT37 has used Python scripts to execute payloads.

T1071.001
Web Protocols
GroupAPT37

APT37 uses HTTPS to conceal C2 communications.

T1082
System Information Discovery
GroupAPT37

APT37 collects the computer name, the BIOS model, and execution path.

T1102.002
Bidirectional Communication
GroupAPT37

APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1106
Native API
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

T1120
Peripheral Device Discovery
GroupAPT37

APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.

T1123
Audio Capture
GroupAPT37

APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input.

T1189
Drive-by Compromise
GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

T1203
Exploitation for Client Execution
GroupAPT37

APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution.

T1204.002
Malicious File
GroupAPT37

APT37 has sent spearphishing attachments attempting to get a user to open them.

T1529
System Shutdown/Reboot
GroupAPT37

APT37 has used malware that will issue the command shutdown /r /t 1 to reboot a system after wiping its MBR.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT37

APT37's has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\.

T1548.002
Bypass User Account Control
GroupAPT37

APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges.

T1555.003
Credentials from Web Browsers
GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

T1559.002
Dynamic Data Exchange
GroupAPT37

APT37 has used Windows DDE for execution of commands and a malicious VBS.

T1561.002
Disk Structure Wipe
GroupAPT37

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR).

T1566.001
Spearphishing Attachment
GroupAPT37

APT37 delivers malware using spearphishing emails with malicious HWP attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.