Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupCobalt Group | Cobalt Group has used Remote Desktop Protocol to conduct lateral movement. |
| T1027.010 Command Obfuscation |
GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1037.001 Logon Script (Windows) |
GroupCobalt Group | Cobalt Group has added persistence by registering the file name for the next stage malware under |
| T1046 Network Service Discovery |
GroupCobalt Group | Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning. |
| T1053.005 Scheduled Task |
GroupCobalt Group | Cobalt Group has created Windows tasks to establish persistence. |
| T1055 Process Injection |
GroupCobalt Group | Cobalt Group has injected code into trusted processes. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1068 Exploitation for Privilege Escalation |
GroupCobalt Group | Cobalt Group has used exploits to increase their levels of rights and privileges. |
| T1070.004 File Deletion |
GroupCobalt Group | Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks. |
| T1071.001 Web Protocols |
GroupCobalt Group | Cobalt Group has used HTTPS for C2. |
| T1071.004 DNS |
GroupCobalt Group | Cobalt Group has used DNS tunneling for C2. |
| T1105 Ingress Tool Transfer |
GroupCobalt Group | Cobalt Group has used public sites such as github.com and sendspace.com to upload files and then download them to victim computers. The group's JavaScript backdoor is also capable of downloading files. |
| T1195.002 Compromise Software Supply Chain |
GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| T1203 Exploitation for Client Execution |
GroupCobalt Group | Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759. |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1218.003 CMSTP |
GroupCobalt Group | Cobalt Group has used the command |
| T1218.008 Odbcconf |
GroupCobalt Group | Cobalt Group has used |
| T1218.010 Regsvr32 |
GroupCobalt Group | Cobalt Group has used regsvr32.exe to execute scripts. |
| T1219 Remote Access Tools |
GroupCobalt Group | Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost. |
| T1220 XSL Script Processing |
GroupCobalt Group | Cobalt Group used msxsl.exe to bypass AppLocker and to invoke Jscript code from an XSL file. |
| T1518.001 Security Software Discovery |
GroupCobalt Group | Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine. |
| T1543.003 Windows Service |
GroupCobalt Group | Cobalt Group has created new services to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupCobalt Group | Cobalt Group has used Registry Run keys for persistence. The group has also set a Startup path to launch the PowerShell shell command and download Cobalt Strike. |
| T1548.002 Bypass User Account Control |
GroupCobalt Group | Cobalt Group has bypassed UAC. |
| T1559.002 Dynamic Data Exchange |
GroupCobalt Group | Cobalt Group has sent malicious Word OLE compound documents to victims. |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
| T1566.002 Spearphishing Link |
GroupCobalt Group | Cobalt Group has sent emails with URLs pointing to malicious documents. |
| T1572 Protocol Tunneling |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1573.002 Asymmetric Cryptography |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
| T1588.002 Tool |
GroupCobalt Group | Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.