ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0073×

21 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1027.010
Command Obfuscation
GroupAPT19

APT19 used Base64 to obfuscate executed commands.

T1027.013
Encrypted/Encoded File
GroupAPT19

APT19 used Base64 to obfuscate payloads.

T1033
System Owner/User Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username.

T1059
Command and Scripting Interpreter
GroupAPT19

APT19 downloaded and launched code within a SCT file.

T1059.001
PowerShell
GroupAPT19

APT19 used PowerShell commands to execute payloads.

T1071.001
Web Protocols
GroupAPT19

APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2.

T1082
System Information Discovery
GroupAPT19

APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine.

T1112
Modify Registry
GroupAPT19

APT19 uses a Port 22 malware variant to modify several Registry keys.

T1132.001
Standard Encoding
GroupAPT19

An APT19 HTTP malware variant used Base64 to encode communications to the C2 server.

T1140
Deobfuscate/Decode Files or Information
GroupAPT19

An APT19 HTTP malware variant decrypts strings using single-byte XOR keys.

T1189
Drive-by Compromise
GroupAPT19

APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets.

T1204.002
Malicious File
GroupAPT19

APT19 attempted to get users to launch malicious attachments delivered via spearphishing emails.

T1218.010
Regsvr32
GroupAPT19

APT19 used Regsvr32 to bypass application control techniques.

T1218.011
Rundll32
GroupAPT19

APT19 configured its payload to inject into the rundll32.exe.

T1543.003
Windows Service
GroupAPT19

An APT19 Port 22 malware variant registers itself as a service.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT19

An APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Debug Tools-%LOCALAPPDATA%\.

T1564.003
Hidden Window
GroupAPT19

APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1566.001
Spearphishing Attachment
GroupAPT19

APT19 sent spearphishing emails with malicious attachments in RTF and XLSM formats to deliver initial exploits.

T1574.001
DLL
GroupAPT19

APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL.

T1588.002
Tool
GroupAPT19

APT19 has obtained and used publicly-available tools like Empire.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.